{"id":"CVE-2025-14754","published":"2026-09-18T16:17:02.253","lastModified":"2026-09-22T12:50:05.347","description":"IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":["ibm"],"products":["cloud pak for data"],"references":[{"url":"https://www.ibm.com/support/pages/node/7287142","tags":["Vendor Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows an authenticated user to execute arbitrary commands with elevated privileges, posing a significant security risk.","exploitability":"Exploitation requires an authenticated user with access to the system, making it moderately difficult to exploit.","blast_radius":"If exploited, this could lead to complete system compromise and data loss.","remediation":"Upgrade to IBM Cloud Pak for Data 5.1.2 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","priv-escalation","auth-required"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:23:56.996Z"}}