ZeroHour

CVE-2026-82095

moderate

Authenticated OS Command Injection RCE in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage running on IBM Cloud Pak for Data 5.4.0.0 contains an OS command injection flaw (CWE-78) in which special elements passed into an operating system command are not properly neutralized. A remote attacker who already holds valid low-privileged credentials can send crafted input that reaches the underlying OS command unsanitized; no user interaction is required. Successful exploitation executes arbitrary commands or code under the DataStage process, with high impact to confidentiality, integrity, and availability per the 8.8 (High) CVSS 3.1 score. Only DataStage deployments on Cloud Pak for Data version 5.4.0.0 are identified as affected in the available data. The issue is not in CISA's KEV catalog and no public proof-of-concept or in-the-wild exploitation is known.

What to do: Check IBM's security bulletin for CVE-2026-82095 and apply the remediation IBM ships for DataStage on Cloud Pak for Data 5.4.0.0 as soon as it is available. Until patched, restrict which authenticated accounts can reach DataStage and audit those credentials, since exploitation requires a valid low-privileged login. Monitor DataStage hosts for unexpected OS command execution and watch IBM PSIRT and CISA feeds for updated exploitation status.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatethousands of enterprise installations (order of magnitude, not a precise count) — DataStage on Cloud Pak for Data is a mainstream enterprise ETL platform deployed in thousands of organizations, but it typically runs inside private data-center Cloud Pak for Data clusters rather than directly internet-exposed, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.