Junglewise Threat Intelligence

CVE-2026-16338: IBM DataStage arbitrary file write via path validation bypass

CVE-2026-16338 · Severity: critical · CVSS 9.9 · Published 2026-09-14

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data is an enterprise data processing and integration platform. A remote authenticated attacker can exploit improper validation of file paths to write arbitrary files to the system, potentially corrupting data, injecting malicious code, or gaining persistent access to the platform.

Technical details

The vulnerability is classified as CWE-73 (External Control of File Name or Path) and results from improper validation of file paths in IBM DataStage. An authenticated attacker with valid credentials can craft malicious file path inputs that bypass path validation checks, allowing arbitrary file writes across the system. The vulnerability requires network access and authentication (PR:L), but has changed scope (S:C), affecting other components or systems. Exploitation enables high-impact integrity compromise, confidentiality violation, and availability impact. IBM has issued patches as part of their Cloud Pak for Data security updates.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-14: disclosed

References

Related threats