TL;DR
IBM disclosed 22 security flaws affecting DataStage on Cloud Pak for Data. The most severe IBM DataStage vulnerabilities allow remote authenticated attackers to execute arbitrary code or cause a denial of service. Administrators must upgrade to version 5.4 patch 7 or later immediately to secure their environments.
- Total: 8 CVEs
- Severity: 1 Critical · 7 High
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-16346
- Action: Apply the latest security updates now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-16346 | 9.9 | CWE-285 | — | Not exploited |
| CVE-2026-17102 | 8.8 | CWE-78 | — | Not exploited |
| CVE-2026-16469 | 8.8 | CWE-78 | — | Not exploited |
| CVE-2026-16672 | 8.8 | has several | — | Not exploited |
| CVE-2026-16468 | 8.8 | CWE-78 | — | Not exploited |
| CVE-2026-0980 | 8.3 | CWE-78 | 0:0.13.0-0.1.el8sat, 0:0.13.0-0.1.el9sat, 0:3.14.0.14-1.el9sat (+12) | Not exploited |
| CVE-2025-9566 | 8.1 | CWE-22 | 5.6.1, 6:5.4.0-13.el10_0, 7:5.6.0-5.el10_1 (+36) | Not exploited |
| CVE-2025-14550 | 7.5 | CWE-407 | 6.0.2, 5.2.11, 4.2.28 (+1) | Not exploited |
Why It Matters
IBM DataStage serves as a core data integration tool for enterprise cloud deployments. A compromise in this layer exposes sensitive corporate data and infrastructure. Among the disclosed flaws, CVE-2026-16346 stands out with a near-perfect CVSS base score of 9.9. This specific flaw allows remote code execution due to improper authorization. Another critical flaw, CVE-2026-82101, scores 9.6 and can trigger a denial of service via path traversal. Furthermore, CVE-2026-81208 reveals a severe credential protection failure. The pull endpoint decrypts sensitive blobs using a shared, unrotated master key. As the advisory notes, “this is cross-tenant: any authenticated user recovers any other tenant’s connection passwords, Git PATS, and IAM API keys”. Currently, no active exploitation in the wild or public proof-of-concept exploits are confirmed. However, the severity of these flaws demands urgent attention from security teams.
How The Attack Works
The reported IBM DataStage vulnerabilities encompass various attack vectors. Several flaws, such as CVE-2026-17102 and CVE-2026-81545, involve OS command injection. In these cases, the system fails to neutralize special elements within OS commands. An authenticated attacker exploits this by injecting malicious commands into the system.
Other vulnerabilities exploit path traversal weaknesses. For example, CVE-2026-84421 occurs due to improper validation of paths during archive extraction. Attackers manipulate file paths to access or overwrite restricted directories. Additionally, CVE-2026-84418 describes a man-in-the-middle attack vector. An attacker presents a forged TLS certificate to intercept connections. The attacker then captures the IAM bearer Authorization header, granting full platform-scope tenant API access.
Affected Versions
These vulnerabilities affect DataStage on Cloud Pak for Data version 5.4.0.0.
Patch Or Mitigation Steps
IBM strongly urges customers to apply the available security updates. Administrators must upgrade DataStage on Cloud Pak for Data to version 5.4 patch 7 or later. Following the official upgrade instructions ensures that all 22 vulnerabilities are successfully remediated. Delaying the patch leaves enterprise data pipelines vulnerable to severe exploitation.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!