CVE-2026-82099: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
Published Sep 7, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
— MITRE
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 10, 2026
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which release is identified as affected?
The provided information identifies IBM DataStage on Cloud Pak for Data version 5.4.0.0.
2
What level of attacker access is required?
Exploitation requires a remote attacker to be authenticated. No user interaction is required.