IBM DataStage: 25 High/Critical CVEs Disclosed Together, Enabling Code Execution and Data Leakage
Key findings • 25 CVEs disclosed for IBM DataStage on Cloud Pak for Data 5.4.0.0 and other IBM products between Sept 23-24, 2026. • Multiple critical and high severity vulnerabilities in Data…

Key findings
- 25 CVEs disclosed for IBM DataStage on Cloud Pak for Data 5.4.0.0 and other IBM products between Sept 23-24, 2026.
- Multiple critical and high severity vulnerabilities in DataStage allow arbitrary code execution and sensitive data disclosure.
- Vulnerabilities span various attack vectors including OS command injection, unsafe deserialization, XXE, and path traversal.
- IBM PowerVM Hypervisor and other products also affected by numerous medium to low severity flaws.
- Users are urged to consult IBM advisories for patches and mitigation strategies for all affected versions.
On September 23-24, 2026, a significant batch of 25 vulnerabilities was disclosed for IBM DataStage on Cloud Pak for Data 5.4.0.0. The vulnerabilities, primarily affecting authenticated users, range in severity from High to Critical, with several allowing for arbitrary code execution or sensitive information disclosure.
A cluster of vulnerabilities in IBM DataStage on Cloud Pak for Data 5.4.0.0 centers on improper handling of OS commands and data deserialization. CVE-2026-82093, CVE-2026-81552, CVE-2026-81548, CVE-2026-81547, CVE-2026-81539, CVE-2026-81537, and CVE-2026-80425 all relate to improper neutralization of special elements used in OS commands or OS command injection, potentially allowing remote authenticated attackers to execute arbitrary commands or code. CVE-2026-81537 and CVE-2026-80412 specifically mention OS command injection and improper escaping of connector property values, respectively, leading to arbitrary code execution. CVE-2026-82093 involves unsafe deserialization, also enabling arbitrary code execution.
Further impacting IBM DataStage, several vulnerabilities focus on sensitive information disclosure. CVE-2026-81549, rated Critical, allows information disclosure due to improper validation of the X-Forwarded-Proto header. CVE-2026-81536, an XML external entity (XXE) injection flaw, also leads to sensitive data disclosure. CVE-2026-81208 involves improper handling of encrypted credentials, allowing attackers to obtain credentials for other users or environments. Additionally, CVE-2026-80423 exposes namespace-wide secrets via accessible file mounts, and CVE-2026-82094 permits directory traversal due to improper limitation of a pathname.
Beyond DataStage, other IBM products were also affected by vulnerabilities disclosed in this batch. IBM Enterprise Build of Quarkus versions 3.27.1 through 3.27.5.SP1 and 3.33.1 through 3.33.3.SP1 are vulnerable to SQL injection (CVE-2026-77874), allowing attackers to view, add, modify, or delete database information. IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 has a path traversal vulnerability in its Admin API log-download endpoint (CVE-2026-77825), enabling authenticated administrators to read log files. IBM Concert versions 1.0.0 through 3.0.0 allow recursive copying of directories without proper controls (CVE-2026-6544), potentially leading to the unintentional inclusion of sensitive files.
Several vulnerabilities were identified in IBM PowerVM Hypervisor across various firmware versions. These include an issue in a hypervisor call interface allowing limited hypervisor memory reads (CVE-2026-19492), an out-of-bounds read leading to sensitive information disclosure (CVE-2026-18870), a vulnerability in the partition resource dump interface allowing limited data retrieval (CVE-2026-17511), a partition firmware runtime vulnerability enabling specially crafted requests (CVE-2026-17504), a partition firmware runtime boot configuration issue allowing NVRAM alteration (CVE-2026-17503), and a vulnerability in the RTAS firmware-to-OS interface allowing specially crafted requests (CVE-2026-17413). IBM OPENBMC firmware also has a vulnerability in its management interface allowing limited BMC internal memory reads or service crashes (CVE-2026-18857). Lastly, IBM Db2 Mirror for i versions 7.6, 7.5, and 7.4 could allow local attackers to obtain sensitive information due to the use of AES ECB mode for encryption (CVE-2026-17104).
The disclosures, occurring on September 23-24, 2026, highlight a broad range of security weaknesses across multiple IBM products. The most severe issues in IBM DataStage on Cloud Pak for Data 5.4.0.0, particularly those allowing arbitrary code execution and sensitive data exfiltration, pose a significant risk to organizations utilizing this platform. Users are strongly advised to consult IBM's official advisories for specific patch information and mitigation strategies for all affected products and versions. The sheer volume and severity of these vulnerabilities underscore the importance of timely patching and security reviews for complex enterprise software.
Vypr Intelligence reported on a subset of these vulnerabilities, specifically highlighting five high/critical flaws in IBM DataStage, including command injection and XXE vulnerabilities. They noted that all affected vulnerabilities impacted version 5.4.0.0 and advised users to consult IBM advisories for patches. Another report from Vypr Intelligence detailed twelve high/critical CVEs in IBM DataStage, emphasizing command execution via OS command injection and improper neutralization, as well as sensitive information disclosure through XXE and exposed secrets. Both reports indicate that all vulnerabilities affect version 5.4.0.0.