CVE-2026-80378
8.5IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw that allows an authenticated remote attacker to cause a denial of service condition.
Executive summary
A remote authenticated attacker can trigger a denial of service condition in IBM DataStage on Cloud Pak for Data 5.4.0.0 due to a flaw in authorization handling.
Vulnerability
This vulnerability is caused by improper authorization (CWE-285), which allows a remote user with authenticated access to perform actions that lead to a denial of service. The CVSS vector of AV:N/AC:L/PR:L/UI:N confirms that the attacker requires low-level privileges but does not require any user interaction to trigger the fault.
Business impact
The ability for an authenticated attacker to cause a denial of service presents a significant threat to operational availability and business continuity. With a CVSS score of 8.5, this high-severity vulnerability could lead to prolonged service outages, hindering critical data processing tasks and impacting downstream business workflows that rely on the DataStage platform.
Remediation
Immediate Action: Upgrade to DataStage on Cloud Pak for Data 5.4 patch 5 or later as specified in the official IBM security bulletin.
Proactive Monitoring: Review system access logs for suspicious user activity or repeated attempts to execute unauthorized functions within the DataStage environment.
Compensating Controls: Ensure that access controls and identity management policies are strictly enforced to limit the number of users with the low-level privileges required to trigger this vulnerability.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Given the high CVSS severity rating, organizations should prioritize the application of the vendor-supplied patch. Administrators must verify their current version and upgrade to version 5.4 patch 5 or later immediately to eliminate the risk of service disruption.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section