VYPR
Vypr IntelligenceAI-generatedSep 14, 2026· 6 CVEs

IBM DataStage: Six High-to-Critical Vulnerabilities Disclosed Together on Sep 14, 2026

Six vulnerabilities, including a critical arbitrary file write flaw, were disclosed in IBM DataStage on Cloud Pak for Data 5.4.0.0 on September 14, 2026.

Key findings

  • Six vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0 were disclosed on September 14, 2026.
  • Critical vulnerability CVE-2026-16338 allows arbitrary file writes due to improper file path validation.
  • High severity flaws enable OS command execution (CVE-2026-16673, CVE-2026-16466) and arbitrary file access (CVE-2026-16335).
  • An XXE injection vulnerability (CVE-2026-16432) could lead to sensitive information disclosure.
  • Arbitrary code execution is possible via improper XSLT transformation configuration (CVE-2026-16428).
  • All vulnerabilities affect version 5.4.0.0 of IBM DataStage on Cloud Pak for Data.

On September 14, 2026, IBM disclosed a batch of six vulnerabilities affecting IBM DataStage on Cloud Pak for Data version 5.4.0.0. These vulnerabilities, all disclosed simultaneously, range in severity from High to Critical, with the most severe allowing for arbitrary file writes. The disclosures highlight significant security weaknesses within the DataStage platform, potentially exposing sensitive data and system integrity.

Several vulnerabilities center on remote command execution. CVE-2026-16673 and CVE-2026-16466, both rated High with a CVSSv3 score of 8.8, stem from improper neutralization of special characters and OS command injection, respectively. These flaws could permit authenticated attackers to run arbitrary OS commands on the affected system. Additionally, CVE-2026-16428, also a High severity flaw (CVSSv3 8.8), arises from improper configuration of the XSLT transformation engine, enabling arbitrary code execution.

Further complicating the security posture, CVE-2026-16335, a High severity path traversal vulnerability (CVSSv3 8.1), allows authenticated attackers to read, write, or delete arbitrary files. Complementing this, CVE-2026-16338, a Critical severity vulnerability (CVSSv3 9.9), involves improper validation of file paths, leading to arbitrary file writes. Lastly, CVE-2026-16432, a High severity flaw (CVSSv3 7.7), is an XML external entity (XXE) injection vulnerability within the PxXMLInput operator, which could allow an attacker to obtain sensitive information.

The simultaneous disclosure of these six vulnerabilities underscores a critical period for IBM DataStage users. The range of impacts, from command execution to arbitrary file manipulation and sensitive data exposure, necessitates immediate attention. All disclosed vulnerabilities affect IBM DataStage on Cloud Pak for Data 5.4.0.0. While the specific patch details are not provided in the disclosure, users are strongly advised to consult IBM's official security advisories for the latest information on mitigation and remediation.

This batch of vulnerabilities presents a significant risk to organizations utilizing IBM DataStage. The ability for authenticated attackers to execute commands, write arbitrary files, and exfiltrate sensitive information requires prompt patching and security review. Users should prioritize updating their DataStage instances to the latest secure versions as recommended by IBM to protect against these threats.

Key Findings:

  • Six vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0 were disclosed on September 14, 2026.
  • Critical vulnerability CVE-2026-16338 allows arbitrary file writes due to improper file path validation.
  • High severity flaws enable OS command execution (CVE-2026-16673, CVE-2026-16466) and arbitrary file access (CVE-2026-16335).
  • An XXE injection vulnerability (CVE-2026-16432) could lead to sensitive information disclosure.
  • Arbitrary code execution is possible via improper XSLT transformation configuration (CVE-2026-16428).
  • All vulnerabilities affect version 5.4.0.0 of IBM DataStage on Cloud Pak for Data.
AI-written article. Grounded in 6 CVE records listed below.
IBM DataStage: Six High-to-Critical Vulnerabilities Disclosed Together on Sep 14, 2026 · VYPR