ZeroHour

CVE-2026-82098

moderate

Authenticated OS Command Injection in IBM DataStage on Cloud Pak for Data

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage, as delivered with IBM Cloud Pak for Data 5.4.0.0, fails to properly neutralize special elements passed into operating system commands (CWE-78), allowing command injection. A remote attacker who holds valid low-privileged authenticated access can trigger the flaw by supplying crafted input to an affected command-execution path, causing arbitrary OS commands to run on the server. Successful exploitation yields full confidentiality, integrity, and availability impact on the host (CVSS 8.8, AV:N/AC:L/PR:L/UI:N), effectively giving the attacker arbitrary command execution in the context of the affected service. Only organizations running DataStage on IBM Cloud Pak for Data 5.4.0.0 are affected; deployments that do not expose this component, or older releases, fall outside the stated scope. As of now there is no evidence of in-the-wild exploitation, no listing in CISA's Known Exploited Vulnerabilities catalog, and no known public proof-of-concept.

What to do: Upgrade DataStage/Cloud Pak for Data 5.4.0.0 to the fixed release or interim fix identified in IBM's security advisory for CVE-2026-82098, checking the IBM fix list for CP4D 5.4. Until patched, restrict authenticated access to DataStage job and command-execution interfaces to trusted users and monitor for suspicious OS command activity from the service. Since no public PoC or KEV entry exists, prioritize by whether the deployment exposes DataStage to non-administrator authenticated users.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderateon the order of hundreds to a few thousand enterprise deployments (likely 1k–10k systems and tens of thousands of users); precise count unknown — Cloud Pak for Data is a self-managed enterprise platform IBM has publicly positioned at thousands of large-enterprise customers, and DataStage is one of several optional services, so affected instances are bounded by that install base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.