ZeroHour

CVE-2026-80380

moderate

Cross-Site Request Forgery in IBM DataStage on Cloud Pak for Data 5.4.0

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to cross-site request forgery (CWE-352), which allows a remote, unauthenticated attacker to trick a logged-in user's browser into sending forged requests to the DataStage web interface. The attack is triggered when an authenticated user follows an attacker-crafted link or loads an attacker-controlled page while their DataStage session is active; the CVSS vector (AV:N/AC:L/PR:N/UI:R) confirms the flaw requires no privileges but does require user interaction, with the forged request executing under the victim's session rights. Successful exploitation yields unauthorized actions with high integrity impact and low availability impact per the CVSS score, meaning an attacker could alter DataStage configurations or data-processing jobs and potentially disrupt processing, while confidentiality (data theft) is not scored. Only organizations running IBM DataStage on Cloud Pak for Data 5.4.0.0 are affected. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.

What to do: Check whether your Cloud Pak for Data deployment runs DataStage 5.4.0.0 and monitor IBM's PSIRT advisory for CVE-2026-80380 for the patched release, then upgrade as IBM directs. Until patched, restrict access to the DataStage console to trusted networks and users (VPN or allowlists), caution users against clicking unsolicited links while authenticated, and review recent job and configuration changes for signs of tampering.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderate≈ low thousands of enterprise installations (order-of-magnitude estimate; IBM publishes no active-install counts) — Cloud Pak for Data with DataStage is an enterprise data-integration platform typically deployed inside private data centers rather than at internet scale, so the population running the specifically named 5.4.0.0 release is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.