CVE-2026-81537
8.8IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data is vulnerable to remote OS command injection, which allows an authenticated attacker to execute arbitrary code on the underlying system.
Executive summary
An authenticated attacker can execute arbitrary code on IBM DataStage on Cloud Pak for Data 5.4.0.0 due to an OS command injection vulnerability.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) that occurs when user-supplied input is not properly sanitized before being passed to a system shell. The vulnerability requires a remote attacker to have authenticated access to the system to trigger the injection.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution on the host server. Given the CVSS score of 8.8, this poses a significant risk to the confidentiality, integrity, and availability of the entire Cloud Pak for Data environment, potentially leading to total system compromise and unauthorized data access.
Remediation
Immediate Action: Upgrade to DataStage on Cloud Pak for Data 5.4 patch 7 or later as specified in the official IBM security documentation.
Proactive Monitoring: Review system and application access logs for suspicious shell commands or unusual child processes originating from the DataStage application service account.
Compensating Controls: Implement strict network segmentation to limit access to the affected management interfaces and ensure that only authorized personnel can reach the application.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical security risk due to the potential for full code execution. Organizations running version 5.4.0.0 should prioritize the application of the vendor-provided patch to 5.4 patch 7 immediately to eliminate the command injection vector.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section