Executive brief
DTStack Taier, a platform for big data development, contains a security flaw that allows authenticated users to execute unauthorized operating system commands. By submitting specially crafted SQL text through the application's programming interface (API), an attacker can gain control over the underlying server. This could lead to the theft of sensitive data, disruption of data processing operations, or full system compromise.
Technical details
A command injection vulnerability exists in DTStack Taier 1.4.0 within the REST API component. The application accepts user-supplied SQL text via the 'sqlText' parameter, stores it in a MySQL database, and subsequently passes it to the Java 'Runtime.exec()' function using a 'sh -c' prefix without proper sanitization or validation. An authenticated attacker with task or job creation permissions can inject shell metacharacters (such as semicolons or backticks) into the SQL text to achieve remote code execution (RCE). While the vendor was notified, no official patch has been confirmed at the time of disclosure; remediation should involve migrating to ProcessBuilder with explicit argument lists and implementing strict input validation.
Affected products
- DTStack Taier 1.4.0
Timeline
- 2026-05-25: disclosed: Public disclosure of the exploit details.
- 2026-05-25: advisory: CVE-2026-9437 published.