CVE-2026-80434
moderateIDOR in IBM DataStage on Cloud Pak for Data 5.4.0.0 lets authenticated users trigger DoS
CVE-2026-80434 is an insecure direct object reference (CWE-639) in the runtime cache handling of IBM DataStage on Cloud Pak for Data, affecting version 5.4.0.0. A remote attacker with low-privilege authenticated access can send crafted requests that reference runtime cache objects they are not authorized to touch, manipulating caches shared across the scoped environment (the CVSS scope is 'changed', meaning other components can be impacted). Successful manipulation causes a denial of service for DataStage jobs and services, with the CVSS vector also indicating a low level of confidentiality and integrity impact. Only organizations running DataStage on Cloud Pak for Data 5.4.0.0 are affected. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and no exploitation has been reported in the wild.
What to do: Upgrade DataStage on Cloud Pak for Data from 5.4.0.0 to the fixed fix pack or later release identified in IBM's security bulletin for this CVE. Until patched, restrict which authenticated low-privilege accounts can invoke jobs or interact with runtime cache resources, and monitor for unusual cache-related job failures or service disruptions. There is no known public exploit, so prioritize patching where untrusted or broadly-issued low-privilege credentials can reach DataStage.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.