CVE-2026-16428
IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.54%
- CWE
- CWE-94
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- IBM DataStage on Cloud Pak for Data
Weakness type
Related vulnerabilities
- CVE-2026-60004 — Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- CVE-2026-76605 — Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2
- CVE-2026-76604 — Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2
- CVE-2026-92937 — vm2 3.11.6 Remote Code Execution via Promise call/apply
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2026-62104 — WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability
- CVE-2026-53710 — MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
- CVE-2026-55565 — Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)