ZeroHour

CVE-2026-80378

moderate

Improper Authorization DoS in IBM DataStage on Cloud Pak for Data 5.4.0

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-80378 is an improper authorization flaw (CWE-285) in IBM DataStage on Cloud Pak for Data 5.4.0.0, assigned by IBM's PSIRT. A remote attacker who already holds valid low-privilege credentials can send requests that the service fails to authorize correctly, triggering a denial of service. The CVSS 8.5 (high) score reflects a high availability impact with a low integrity impact and no confidentiality impact, and the scope-changed metric suggests the disruption can extend beyond the vulnerable component itself. Only organizations running the affected DataStage service on Cloud Pak for Data 5.4.0.0 are exposed, and exploitation requires an authenticated account. There is currently no known exploitation in the wild, no CISA KEV listing, and no public proof-of-concept.

What to do: Inventory your Cloud Pak for Data estate to find any environments running DataStage on 5.4.0.0, and monitor IBM's security bulletin for CVE-2026-80378 to obtain the fixed release and apply it promptly. Until patched, restrict authenticated DataStage access to least-privilege, trusted users and watch for unexpected service outages or restarts in the DataStage service. Because exploitation requires valid credentials and no public PoC or in-the-wild activity is known, this is a prioritized-patch item rather than an emergency, but shared or multi-tenant clusters warrant faster remediation.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderatelikely on the order of 1,000–10,000 enterprise deployments/users (subset of the IBM Cloud Pak for Data install base running the specific 5.4.0.0 point release) — Cloud Pak for Data is IBM's flagship enterprise data platform with DataStage among its most deployed services, but the affected footprint is limited to a single point release, exploitation requires authenticated access, and no public scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.