Junglewise Threat Intelligence

CVE-2026-16468: IBM DataStage OS command injection

CVE-2026-16468 · Severity: high · CVSS 8.8 · Published 2026-09-22

Technologies: IBM DataStage, IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data is a data integration and transformation tool used by enterprises to build and manage data pipelines. A remote authenticated attacker can inject and execute arbitrary operating system commands through improper input validation, potentially gaining full system access and compromising sensitive data.

Technical details

OS command injection in DataStage due to improper neutralization of special elements in OS commands (CWE-78). The vulnerability requires prior authentication and network access. An authenticated attacker can execute arbitrary commands with the privileges of the DataStage service process, leading to complete system compromise. IBM has issued patches for this vulnerability.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats