CVE-2026-16673
8.8IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data is vulnerable to remote command execution via improper neutralization of special characters in the PxPeek name property by an authenticated attacker.
Executive summary
An authenticated remote attacker can execute arbitrary operating system commands on IBM DataStage on Cloud Pak for Data 5.4.0.0, posing a critical risk of full system compromise.
Vulnerability
The application fails to properly sanitize input within the PxPeek name property. This allows a remote authenticated user to inject malicious input, resulting in arbitrary OS command execution with the privileges of the application service.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute system-level commands, leading to complete unauthorized control over the affected DataStage instance. Given the CVSS score of 8.8, this flaw presents a high risk for data exfiltration, unauthorized modification of sensitive business data, and potential lateral movement within the network.
Remediation
Immediate Action: Upgrade the DataStage on Cloud Pak for Data environment to version 5.4 patch 5 or later as specified in the official IBM support documentation.
Proactive Monitoring: Review system and application access logs for unusual command executions or unexpected process spawning associated with the DataStage service account.
Compensating Controls: Implement strict network segmentation and apply egress filtering to limit the impact of potential command execution, and utilize WAF rules to monitor for suspicious command-related character sequences.
Exploitation status
Public Exploit Available: No — exploit_available is unknown.
Analyst recommendation
The severity of this vulnerability, combined with the potential for total system compromise, requires immediate remediation. Administrators should prioritize the upgrade to version 5.4 patch 5 to eliminate the command injection vector. Failure to patch may expose the core data processing infrastructure to complete takeover by a malicious authenticated actor.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section