VYPR
Vypr IntelligenceAI-generatedSep 23, 2026· 12 CVEs

IBM DataStage: Twelve High/Critical CVEs Disclosed, Including Critical Command Injection

IBM DataStage on Cloud Pak for Data 5.4.0.0 faces twelve high/critical CVEs, including critical command injection flaws, disclosed Sep 22-23, 2026.

Key findings

  • Twelve high and critical vulnerabilities disclosed for IBM DataStage on Cloud Pak for Data 5.4.0.0 between Sep 22-23, 2026.
  • Multiple flaws allow arbitrary command or code execution via OS command injection and improper neutralization.
  • Critical CVE-2026-16346 (CVSS 9.9) is among the disclosed command execution vulnerabilities.
  • Other vulnerabilities include sensitive information disclosure via XXE, credential access, and exposed secrets.
  • All vulnerabilities affect version 5.4.0.0; users should consult IBM advisories for patches.

On September 22-23, 2026, a significant batch of twelve high and critical severity vulnerabilities was disclosed for IBM DataStage on Cloud Pak for Data version 5.4.0.0. These vulnerabilities, primarily revolving around OS command injection and improper handling of special elements in commands, could allow remote authenticated attackers to execute arbitrary code, commands, or obtain sensitive information. The coordinated disclosure highlights potential risks for organizations relying on this data integration platform.

Several vulnerabilities fall under the category of OS command injection or improper neutralization of special elements used in OS commands, enabling arbitrary command execution. These include CVE-2026-81537, CVE-2026-80425, CVE-2026-80379, CVE-2026-17102, CVE-2026-16672, CVE-2026-16469, CVE-2026-16468, and CVE-2026-16346. Notably, CVE-2026-16346 was rated as Critical with a CVSSv3 score of 9.9, while the others were rated High with a CVSSv3 score of 8.8. The related news coverage specifically called out five of these command injection flaws, including the critical CVE-2026-16346, as being disclosed on September 22, 2026.

Beyond direct command execution, other vulnerabilities in the batch allow for information disclosure. CVE-2026-80423, a High severity flaw (CVSSv3 8.8), permits remote authenticated attackers to obtain sensitive information through the exposure of namespace-wide secrets via accessible file mounts. Additionally, CVE-2026-81536, also High severity (CVSSv3 7.7), involves an XML external entity (XXE) injection that could lead to sensitive information disclosure. Another High severity vulnerability, CVE-2026-81208 (CVSSv3 7.7), stems from improper handling of encrypted credentials, potentially allowing an authenticated user to access sensitive information.

Further compounding the risk, CVE-2026-80412, a High severity vulnerability (CVSSv3 8.8), involves improper escaping of connector property values during OSH script generation, which could lead to arbitrary code execution.

All twelve disclosed vulnerabilities affect IBM DataStage on Cloud Pak for Data version 5.4.0.0. IBM has provided security advisories detailing these issues. Users are strongly recommended to consult IBM's official documentation for specific patching instructions and mitigation strategies to protect their environments from these critical and high-severity threats.

This coordinated disclosure of multiple, severe vulnerabilities in IBM DataStage underscores the importance of timely patching and security vigilance for users of the Cloud Pak for Data platform. The concentration of command injection and information disclosure flaws highlights critical areas for administrators to focus on when assessing their security posture and applying necessary updates. Organizations should prioritize addressing these vulnerabilities to prevent potential exploitation and maintain the integrity of their data processing workflows.

AI-written article. Grounded in 12 CVE records listed below.