CVE-2026-16469: DataStage on Cloud Pak for Data has several vulnerabilities
IBM DataStage on Cloud Pak for Data 5.4.0.0 px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage px-runtime could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4Patch patch 7
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be remotely authenticated and have privileges sufficient to reach the vulnerable px-runtime functionality. No user interaction is required.
What could a successful exploit allow?
A successful OS command injection could allow execution of arbitrary commands. The reported impact includes high confidentiality, integrity, and availability impact.