CVE-2026-80436
8.5IBM · DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to a denial of service attack, allowing an authenticated remote attacker to delete arbitrary RabbitMQ queues or exchanges.
Executive summary
An authenticated remote attacker can cause a denial of service in IBM DataStage on Cloud Pak for Data 5.4.0.0 by exploiting improper authorization to delete critical messaging queues.
Vulnerability
This vulnerability involves improper authorization (CWE-285) within the messaging infrastructure, which allows an authenticated user to perform unauthorized actions on RabbitMQ queues and exchanges.
Business impact
The ability to delete RabbitMQ queues or exchanges directly impacts the availability of data processing pipelines, leading to significant system downtime and operational disruption. Given the CVSS score of 8.5, this high-severity flaw poses a substantial risk to business continuity, as it allows a malicious or compromised user to cripple critical data integration workflows.
Remediation
Immediate Action: Upgrade to DataStage on Cloud Pak for Data 5.4 patch 5 or later as specified in the official IBM security advisory.
Proactive Monitoring: Review system access logs for unusual administrative activity or unauthorized attempts to interact with the RabbitMQ management interface.
Compensating Controls: Implement strict role-based access control (RBAC) to limit the number of users with permissions to modify messaging infrastructure.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent potential service disruptions. Administrators must prioritize applying the vendor-supplied patch to version 5.4 patch 5 or higher to resolve the underlying authorization flaw and restore secure messaging operations.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section