IBM DataStage: Five Command Injection and XXE Flaws Disclosed Together
Five High/Critical vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0 were disclosed together, including critical command execution flaws.

Key findings
- Five High/Critical vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0 disclosed Sept 22-23, 2026.
- Critical CVE-2026-16346 (CVSS 9.9) allows arbitrary command execution via OS command injection.
- Other flaws include OS command injection, improper neutralization, and XXE for sensitive data disclosure.
- All vulnerabilities affect version 5.4.0.0; users should consult IBM advisories for patches.
On September 22-23, 2026, a batch of five high and critical vulnerabilities was disclosed for IBM DataStage on Cloud Pak for Data version 5.4.0.0. The vulnerabilities, primarily involving OS command injection and improper neutralization of special elements, could allow remote authenticated attackers to execute arbitrary code or commands, or obtain sensitive information. The disclosures occurred within a 24-hour window, highlighting a concentrated disclosure event for this component.
The most severe of these flaws is CVE-2026-16346, a critical vulnerability with a CVSSv3 score of 9.9. This flaw, along with CVE-2026-17102, stems from improper neutralization of special elements used in OS commands, potentially allowing for arbitrary command execution. Both were disclosed on September 22, 2026.
Further compounding the risk, CVE-2026-81537 and CVE-2026-80412, both rated as High severity with CVSSv3 scores of 8.8, also involve OS command injection or related issues. CVE-2026-81537 specifically points to OS command injection, while CVE-2026-80412 is due to improper escaping of connector property values during OSH script generation, both enabling arbitrary code execution. These were disclosed on September 23, 2026.
Adding to the attack surface, CVE-2026-81536, a High severity vulnerability (CVSSv3 7.7), allows a remote authenticated attacker to obtain sensitive information through an XML external entity (XXE) injection. This vulnerability was also disclosed on September 23, 2026.
All disclosed vulnerabilities affect IBM DataStage on Cloud Pak for Data version 5.4.0.0. Users are advised to consult IBM's official advisories for specific patch information and mitigation strategies. The concentrated nature of these disclosures suggests a need for prompt attention from administrators managing this platform.
The cluster of vulnerabilities, particularly those enabling arbitrary command execution, underscores the importance of timely patching and security reviews for critical data processing components like IBM DataStage. Users should prioritize applying updates to mitigate the risk of exploitation.
The disclosures were reported by Vypr Intelligence, noting that a total of twelve high and critical vulnerabilities were disclosed for IBM DataStage on Cloud Pak for Data 5.4.0.0 between September 22-23, 2026. This batch of five CVEs represents a significant portion of that event.