CVE-2026-80425

8.8

IBM · DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing remote authenticated attackers to execute arbitrary system commands.

Executive summary

A critical OS command injection vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 allows remote authenticated attackers to achieve full system compromise.

Vulnerability

The vulnerability is classified as CWE-78 (OS Command Injection), resulting from the improper neutralization of special elements within OS commands. An attacker with authenticated access can leverage this flaw to execute arbitrary commands on the underlying host operating system.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute unauthorized code with the privileges of the application service. Given the CVSS score of 8.8, this poses a severe risk of data exfiltration, service disruption, and complete loss of confidentiality, integrity, and availability for the affected DataStage instance.

Remediation

Immediate Action: Upgrade IBM DataStage on Cloud Pak for Data to version 5.4 patch 7 or later as specified in the official IBM security advisory.

Proactive Monitoring: Review system and application access logs for unusual command executions, unexpected process spawning, or suspicious character strings in input fields.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to filter malicious payloads targeting command injection vectors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk due to the potential for remote code execution within the DataStage environment. Administrators must prioritize the application of the vendor-provided patch to version 5.4 patch 7 immediately. Failure to remediate this flaw exposes the infrastructure to potential unauthorized control and data compromise.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources