CVE-2026-16346Critical· 9.9▾ MidnightIBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
datastage_on_cloud_pak_for_data 5.4.0.0IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0Upgrade to 5.4 patch 7 or later by following these instructions.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-16468High· 8.8DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-16469High· 8.8DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-16672High· 8.8DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-17102High· 8.8DataStage on Cloud Pak for Data has several vulnerabilities
CVE-2026-84241High· 8.1IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.
CVE-2026-84076High· 7.6IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.