ZeroHour

CVE-2026-82099

moderate

Authenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4.0

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 fails to properly neutralize special elements passed into operating system commands, allowing command injection (CWE-78). A remote attacker who already holds valid authenticated credentials can trigger the flaw over the network without user interaction. Successful exploitation yields full command execution on the host, giving the attacker high confidentiality, integrity, and availability impact — effectively complete control of the DataStage service context. Only organizations running IBM DataStage on Cloud Pak for Data version 5.4.0.0 are affected, and because valid credentials are required, exposure is limited to environments where an authenticated (including low-privilege) account is compromised or misused. As of now there are no reports of in-the-wild exploitation and no public proof-of-concept.

What to do: Check IBM's security advisory (IBM PSIRT is the CNA) and apply the remediated Cloud Pak for Data 5.4.0 fix release or interim fix as soon as it is available. In the meantime, limit DataStage access to trusted authenticated users, review and rotate low-privilege service and user credentials that can reach DataStage job/command functions, and monitor DataStage and OS logs for unexpected command execution. Note that clusters behind internal networks remain at risk from any compromised authenticated account, so patching is the primary mitigation.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatelikely on the order of thousands of enterprise deployments (subset of the Cloud Pak for Data installed base on 5.4.0.0 with DataStage enabled) — Cloud Pak for Data is an enterprise on-premises/private-cloud analytics platform with an installed base in the low thousands of clusters, and DataStage is among its most widely deployed services, so only clusters on the 5.4.0.0 release…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.