CVE-2026-80380
moderateCross-Site Request Forgery in IBM DataStage on Cloud Pak for Data 5.4.0
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to cross-site request forgery (CWE-352), which allows a remote, unauthenticated attacker to trick a logged-in user's browser into sending forged requests to the DataStage web interface. The attack is triggered when an authenticated user follows an attacker-crafted link or loads an attacker-controlled page while their DataStage session is active; the CVSS vector (AV:N/AC:L/PR:N/UI:R) confirms the flaw requires no privileges but does require user interaction, with the forged request executing under the victim's session rights. Successful exploitation yields unauthorized actions with high integrity impact and low availability impact per the CVSS score, meaning an attacker could alter DataStage configurations or data-processing jobs and potentially disrupt processing, while confidentiality (data theft) is not scored. Only organizations running IBM DataStage on Cloud Pak for Data 5.4.0.0 are affected. There is currently no evidence of exploitation: the flaw is not in CISA's KEV catalog and no public proof-of-concept is known.
What to do: Check whether your Cloud Pak for Data deployment runs DataStage 5.4.0.0 and monitor IBM's PSIRT advisory for CVE-2026-80380 for the patched release, then upgrade as IBM directs. Until patched, restrict access to the DataStage console to trusted networks and users (VPN or allowlists), caution users against clicking unsolicited links while authenticated, and review recent job and configuration changes for signs of tampering.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.