CVE-2026-82095
moderateAuthenticated OS Command Injection RCE in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage running on IBM Cloud Pak for Data 5.4.0.0 contains an OS command injection flaw (CWE-78) in which special elements passed into an operating system command are not properly neutralized. A remote attacker who already holds valid low-privileged credentials can send crafted input that reaches the underlying OS command unsanitized; no user interaction is required. Successful exploitation executes arbitrary commands or code under the DataStage process, with high impact to confidentiality, integrity, and availability per the 8.8 (High) CVSS 3.1 score. Only DataStage deployments on Cloud Pak for Data version 5.4.0.0 are identified as affected in the available data. The issue is not in CISA's KEV catalog and no public proof-of-concept or in-the-wild exploitation is known.
What to do: Check IBM's security bulletin for CVE-2026-82095 and apply the remediation IBM ships for DataStage on Cloud Pak for Data 5.4.0.0 as soon as it is available. Until patched, restrict which authenticated accounts can reach DataStage and audit those credentials, since exploitation requires a valid low-privileged login. Monitor DataStage hosts for unexpected OS command execution and watch IBM PSIRT and CISA feeds for updated exploitation status.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.