CVE-2026-81539: IBM DataStage on Cloud Pak for Data vulnerability
Published Sep 21, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Event History
Sep 21, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker must be remote and authenticated to the affected IBM DataStage on Cloud Pak for Data deployment.
2
Can an unauthenticated internet user exploit this issue directly?
The available information identifies this as an authenticated vulnerability. It does not indicate that unauthenticated exploitation is possible.