SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16432

HIGH · CVSS 7.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The IBM DataStage PxXMLInput operator in Cloud Pak for Data 5.4.0.0 is vulnerable to XML external entity (XXE) injection, which could enable a remote authenticated attacker to access sensitive information. Organizations utilizing this version of IBM DataStage should prioritize remediation efforts to mitigate the risk of data exposure.

CVE
CVE-2026-16432
Severity
HIGH
CVSS
7.7
EPSS
0.34%

Original NVD Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.