ZeroHour

CVE-2026-81550

niche

Authenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an OS command injection flaw (CWE-78) in which special elements in user-supplied input are not properly neutralized before being passed to an operating system command. A remote attacker who holds valid (low-privilege, authenticated) credentials can trigger the flaw over the network without any user interaction. Successful exploitation allows arbitrary code execution on the server, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected organizations are those running the 5.4.0.0 release of DataStage on IBM Cloud Pak for Data. There is no evidence of active exploitation, no known public proof-of-concept, and the issue is not yet listed in CISA's KEV catalog.

What to do: Check IBM's security advisory and fix distribution (Fix Central / Cloud Pak for Data update channel) for a patched DataStage on Cloud Pak for Data 5.4.0.0 release and apply it promptly. Until patched, restrict DataStage access to trusted authenticated users, review account permissions, and monitor for unexpected child process or OS command execution on DataStage hosts. Since no public PoC or in-the-wild exploitation is known, there is no urgent emergency patching, but enterprise ETL servers often hold sensitive data pipelines, so treat this as high priority.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nicheroughly hundreds to a few thousand enterprise deployments running DataStage on Cloud Pak for Data, limited to the 5.4.0.0 release — DataStage on Cloud Pak for Data is an enterprise ETL product deployed inside managed data-platform environments rather than internet-facing mass-market software, and only the single 5.4.0.0 release is named as affected, so the plausible…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.