CVE-2026-16346: DataStage on Cloud Pak for Data has several vulnerabilities
IBM DataStage could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 7
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The affected version identified in the available data is IBM DataStage on Cloud Pak for Data 5.4.0.0.
What access does an attacker need to exploit this issue?
An attacker must be remotely reachable and authenticated with low privileges. No user interaction is required.
What could a successful exploit allow?
A successful exploit could allow arbitrary OS command execution. The provided severity vector indicates high impact to confidentiality, integrity, and availability, including impact beyond the initially vulnerable security scope.