Junglewise Threat Intelligence

CVE-2026-16469: IBM DataStage on Cloud Pak for Data OS command injection in px-runtime

CVE-2026-16469 · Severity: high · CVSS 8.8 · Published 2026-09-22

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data is a data integration platform used to design and execute data pipelines. A remote authenticated attacker can execute arbitrary commands on the server by sending specially crafted input that bypasses command sanitization in the px-runtime component, potentially compromising the entire system and accessing sensitive data.

Technical details

The vulnerability is an OS command injection (CWE-78) in DataStage's px-runtime component caused by improper neutralization of special elements in command construction. An authenticated attacker with network access can inject shell metacharacters to execute arbitrary system commands with the privileges of the DataStage process, achieving code execution and full system compromise.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-22: disclosed

References

Related threats