Junglewise Threat Intelligence

CVE-2026-81550: IBM DataStage on Cloud Pak for Data OS command injection

CVE-2026-81550 · Severity: high · CVSS 8.8 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage is a data integration tool used for designing, developing, and executing data pipelines. A remote authenticated attacker can execute arbitrary operating system commands due to improper input validation in command processing, potentially leading to full system compromise including data theft, modification, or destruction.

Technical details

The vulnerability is an OS command injection (CWE-78) affecting IBM DataStage on Cloud Pak for Data 5.4.0.0, caused by improper neutralization of special elements in OS commands. An authenticated attacker with network access can inject malicious commands that will be executed with the privileges of the DataStage service. The attack requires valid authentication credentials but no user interaction. Successful exploitation allows an attacker to achieve complete code execution on the system, enabling data exfiltration, lateral movement, and denial of service.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats