Junglewise Threat Intelligence

CVE-2026-16428: IBM DataStage code injection in XSLT transformation engine

CVE-2026-16428 · Severity: high · CVSS 8.8 · Published 2026-09-14

Technologies: IBM DataStage. Vendors: IBM.

Executive brief

IBM DataStage is a data integration and transformation platform used within Cloud Pak for Data to process and move data across enterprise systems. Due to improper configuration of the XSLT transformation engine, a remote authenticated user can inject and execute arbitrary code on the DataStage system. An attacker with valid credentials could compromise the confidentiality, integrity, and availability of data processing operations and the underlying infrastructure.

Technical details

This vulnerability stems from improper control of XSLT transformation generation (CWE-94), allowing code injection into the XSLT engine. The affected component is the XSLT transformation engine within IBM DataStage on Cloud Pak for Data version 5.4.0.0. The vulnerability requires network access and valid authentication credentials, with no user interaction needed. A remote authenticated attacker can execute arbitrary code with the privileges of the DataStage service, leading to full system compromise. IBM has published this vulnerability in their security bulletin; patch availability should be verified through IBM's support portal.

Affected products

  • IBM DataStage 5.4.0.0

Timeline

  • 2026-09-14: disclosed

References

Related threats