CVE-2026-16673: IBM DataStage on Cloud Pak for Data vulnerability
Published Sep 7, 2026
·Updated
IBM DataStage could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special characters in the PxPeek name property.
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker must be remotely authenticated to exploit the vulnerability.
2
What input is involved in exploitation?
The issue is in improper neutralization of special characters in the PxPeek name property. Exploitation could allow arbitrary operating-system command execution.