ZeroHour

CVE-2026-80436

moderate

Authenticated DoS via RabbitMQ Queue Deletion in IBM DataStage on Cloud Pak for Data

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw (CWE-285) in its handling of RabbitMQ messaging resources. A remote attacker who holds valid, low-privileged credentials can delete arbitrary RabbitMQ queues or exchanges because the affected component does not properly enforce authorization checks. Because the CVSS score includes scope change and high availability impact with no confidentiality impact, the attacker's gain is disruption: message routing and dependent data pipelines fail, producing a denial of service rather than data disclosure. Only organizations running DataStage on Cloud Pak for Data 5.4.0.0 are confirmed affected, and risk is concentrated where untrusted or broadly shared accounts can reach the deployment. The vulnerability is not listed in CISA's KEV, no public proof-of-concept is known, and no exploitation has been reported.

What to do: Inventory Cloud Pak for Data deployments to determine whether DataStage 5.4.0.0 is installed, and consult IBM's security advisory (assigned by IBM PSIRT) for the fixed release or interim fix, then upgrade when IBM publishes one. Until patched, restrict authenticated access to DataStage and any RabbitMQ management interfaces to trusted personnel and monitor for unexpected queue or exchange deletions. Note that no public proof-of-concept or in-the-wild exploitation is currently known.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
moderate≈1,000–10,000 enterprise deployments (rough estimate; no public install counts) — No public install counts exist for this product; the estimate reflects DataStage's long-standing enterprise ETL install base narrowed by the version-specific Cloud Pak for Data 5.4.0.0 scope and the fact that exploitation requires an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.