CVE-2026-80378
moderateImproper Authorization DoS in IBM DataStage on Cloud Pak for Data 5.4.0
CVE-2026-80378 is an improper authorization flaw (CWE-285) in IBM DataStage on Cloud Pak for Data 5.4.0.0, assigned by IBM's PSIRT. A remote attacker who already holds valid low-privilege credentials can send requests that the service fails to authorize correctly, triggering a denial of service. The CVSS 8.5 (high) score reflects a high availability impact with a low integrity impact and no confidentiality impact, and the scope-changed metric suggests the disruption can extend beyond the vulnerable component itself. Only organizations running the affected DataStage service on Cloud Pak for Data 5.4.0.0 are exposed, and exploitation requires an authenticated account. There is currently no known exploitation in the wild, no CISA KEV listing, and no public proof-of-concept.
What to do: Inventory your Cloud Pak for Data estate to find any environments running DataStage on 5.4.0.0, and monitor IBM's security bulletin for CVE-2026-80378 to obtain the fixed release and apply it promptly. Until patched, restrict authenticated DataStage access to least-privilege, trusted users and watch for unexpected service outages or restarts in the DataStage service. Because exploitation requires valid credentials and no public PoC or in-the-wild activity is known, this is a prioritized-patch item rather than an emergency, but shared or multi-tenant clusters warrant faster remediation.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.