IBM has released a major security bulletin addressing twenty-five flaws in DataStage on Cloud Pak for Data, including six CVEs overall. The advisory highlights that the vulnerabilities could allow an authenticated attacker to write arbitrary files and, in some cases, execute code on the underlying server. Among the flaws, the highest-severity issue is CVE-2026-16338, rated 9.9 on CVSSv3, which stems from improper validation of file paths and could enable remote authenticated file writes.
The bulletin also notes server-side request forgery (SSRF) and path traversal issues that could enable attackers to reach co‑tenant services, internal interfaces, or to write to or delete files on shared storage. Open source components used within DataStage on Cloud Pak for Data are mentioned as part of the processing stack.
Affected versions and practical response: The vulnerabilities impact IBM DataStage on Cloud Pak for Data version 5.4.0[.]0. IBM states there is no confirmed exploitation in the wild and no public PoC exploits at present. Administrators should upgrade to version 5.4 patch 5 or later to mitigate the issues. The vendor urges immediate action, and organisations are advised to tighten cluster network access and enforce strong tenant isolation until patches are applied.
In addition to applying updates, the advisory recommends restricting network exposure and reviewing platform isolation to reduce risk across shared environments. CVEs noted in the report include CVE-2026-82107 (SSRF), CVE-2026-82100 (remote impact on data stages), CVE-2026-81551 (path traversal leading to writes/deletes on shared storage), and several others listed as Not Exploited in the public record.