CVE-2026-82099
moderateAuthenticated OS Command Injection in IBM DataStage on Cloud Pak for Data 5.4.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 fails to properly neutralize special elements passed into operating system commands, allowing command injection (CWE-78). A remote attacker who already holds valid authenticated credentials can trigger the flaw over the network without user interaction. Successful exploitation yields full command execution on the host, giving the attacker high confidentiality, integrity, and availability impact — effectively complete control of the DataStage service context. Only organizations running IBM DataStage on Cloud Pak for Data version 5.4.0.0 are affected, and because valid credentials are required, exposure is limited to environments where an authenticated (including low-privilege) account is compromised or misused. As of now there are no reports of in-the-wild exploitation and no public proof-of-concept.
What to do: Check IBM's security advisory (IBM PSIRT is the CNA) and apply the remediated Cloud Pak for Data 5.4.0 fix release or interim fix as soon as it is available. In the meantime, limit DataStage access to trusted authenticated users, review and rotate low-privilege service and user credentials that can reach DataStage job/command functions, and monitor DataStage and OS logs for unexpected command execution. Note that clusters behind internal networks remain at risk from any compromised authenticated account, so patching is the primary mitigation.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.