CVE-2026-16428

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to remote code execution due to improper configuration of the XSLT transformation engine.

Executive summary

An authenticated attacker can execute arbitrary code on IBM DataStage on Cloud Pak for Data 5.4.0.0 by exploiting an insecure XSLT transformation engine configuration.

Vulnerability

This vulnerability involves improper control of code generation (CWE-94) within the XSLT transformation engine, which allows an authenticated attacker to achieve remote code execution. The attack requires low-privileged network access to the application.

Business impact

The ability for an authenticated user to execute arbitrary code poses a critical risk to data confidentiality, integrity, and system availability. With a CVSS score of 8.8, this high-severity flaw could allow an attacker to gain full control over the DataStage environment, potentially leading to unauthorized data exfiltration or total system compromise.

Remediation

Immediate Action: Upgrade to version 5.4 patch 5 or later as specified in the official IBM support documentation.

Proactive Monitoring: Review system access logs for unusual XSLT processing requests or unexpected child processes spawned by the DataStage service.

Compensating Controls: Implement strict network segmentation and ensure that only authorized personnel have access to the DataStage management interface to minimize the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution, organizations running IBM DataStage on Cloud Pak for Data version 5.4.0.0 must prioritize applying the vendor-provided patch. Administrators should transition to version 5.4 patch 5 immediately to eliminate this vulnerability and prevent potential exploitation by malicious actors.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources