Junglewise Threat Intelligence

CVE-2026-16673: IBM DataStage command injection in PxPeek name property

CVE-2026-16673 · Severity: high · CVSS 8.8 · Published 2026-09-14

Technologies: IBM DataStage. Vendors: IBM.

Executive brief

IBM DataStage is a data integration tool used to build and manage data pipelines. A vulnerability in the PxPeek component allows authenticated users to inject arbitrary operating system commands through improper handling of special characters, potentially leading to unauthorized command execution and system compromise.

Technical details

This vulnerability is an OS command injection (CWE-78) in the PxPeek operator of IBM DataStage. The vulnerability stems from improper neutralization of special characters in the PxPeek name property, allowing authenticated attackers to construct malicious payloads that break out of intended command context. The attack requires valid authentication credentials and network access to the DataStage service, with no additional user interaction required. Successful exploitation enables arbitrary operating system command execution with the privileges of the DataStage service process, potentially leading to full system compromise. Patches are expected from IBM as part of their security update process.

Affected products

  • IBM DataStage 5.4.0.0

Timeline

  • 2026-09-14: disclosed

References

Related threats