VYPR
Vypr IntelligenceAI-generatedSep 22, 2026· 5 CVEs

IBM DataStage: Five Command Injection Flaws Disclosed, One Critical

Five vulnerabilities, including a critical OS command injection flaw, were disclosed for IBM DataStage on Cloud Pak for Data 5.4.0.0 on September 22, 2026.

Key findings

  • Five vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0 disclosed on Sep 22, 2026.
  • All flaws involve OS command injection or improper neutralization of command elements.
  • Vulnerabilities range from High (CVSS 8.8) to Critical (CVSS 9.9).
  • A critical CVE-2026-16346 allows arbitrary command execution.
  • Affected product version is IBM DataStage on Cloud Pak for Data 5.4.0.0.

On September 22, 2026, a batch of five vulnerabilities was disclosed for IBM DataStage on Cloud Pak for Data, with a critical severity flaw leading the pack. These vulnerabilities, all stemming from improper neutralization of special elements in OS commands or direct OS command injection, could allow a remote authenticated attacker to execute arbitrary commands or code. The affected product version is specifically identified as 5.4.0.0.

The disclosed vulnerabilities include:

  • CVE-2026-17102: A high-severity vulnerability (CVSSv3 8.8) allowing arbitrary command execution due to improper neutralization of OS command elements.
  • CVE-2026-16672: Another high-severity flaw (CVSSv3 8.8) enabling arbitrary code execution, also attributed to improper neutralization of OS command elements.
  • CVE-2026-16469: This high-severity vulnerability (CVSSv3 8.8) affects the px-runtime component of DataStage and permits arbitrary command execution via improper neutralization of OS command elements.
  • CVE-2026-16468: A high-severity vulnerability (CVSSv3 8.8) that allows arbitrary command execution due to OS command injection.
  • CVE-2026-16346: The most severe vulnerability, rated critical (CVSSv3 9.9), which enables arbitrary command execution due to improper neutralization of OS command elements.

All five vulnerabilities share a common root cause: the improper handling of user-supplied input that is used in operating system commands. This allows authenticated attackers to inject malicious commands, potentially leading to full system compromise. The consistent nature of these flaws across multiple CVEs suggests a systemic issue in how DataStage processes external commands.

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is confirmed to be affected by all these vulnerabilities. While the disclosures do not mention specific threat actors or in-the-wild exploitation, the severity of these flaws, particularly the critical CVE-2026-16346, warrants immediate attention from administrators.

As of the disclosure date, the provided information does not specify patch versions or detailed mitigation steps beyond the general advice to update the software. Users are strongly advised to consult IBM's official security advisories for the latest information on patches and recommended actions to secure their DataStage deployments.

The coordinated disclosure of these five command injection and arbitrary command execution vulnerabilities highlights a significant risk for organizations using IBM DataStage on Cloud Pak for Data 5.4.0.0. Prompt patching and security diligence are essential to prevent potential exploitation and maintain the integrity of data processing environments. Users should remain vigilant for any further updates or security bulletins from IBM regarding these issues.

AI-written article. Grounded in 5 CVE records listed below.
IBM DataStage: Five Command Injection Flaws Disclosed, One Critical · VYPR