---
id: CVE-2026-14350
title: >-
  IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an
  unauthorized user to inject data into log messages due to improper
  neutralization of special elements when written to log files.
summary: >-
  IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an
  unauthorized user to inject data into log messages due to improper
  neutralization of special elements when written to log files.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-117
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:17:08.940'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14350'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286036'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00226
epssPercentile: 0.11903
ingestedAt: '2026-09-08T15:33:26.962Z'
---

## Overview

IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
