CVE-2026-80436
moderateAuthenticated DoS via RabbitMQ Queue Deletion in IBM DataStage on Cloud Pak for Data
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw (CWE-285) in its handling of RabbitMQ messaging resources. A remote attacker who holds valid, low-privileged credentials can delete arbitrary RabbitMQ queues or exchanges because the affected component does not properly enforce authorization checks. Because the CVSS score includes scope change and high availability impact with no confidentiality impact, the attacker's gain is disruption: message routing and dependent data pipelines fail, producing a denial of service rather than data disclosure. Only organizations running DataStage on Cloud Pak for Data 5.4.0.0 are confirmed affected, and risk is concentrated where untrusted or broadly shared accounts can reach the deployment. The vulnerability is not listed in CISA's KEV, no public proof-of-concept is known, and no exploitation has been reported.
What to do: Inventory Cloud Pak for Data deployments to determine whether DataStage 5.4.0.0 is installed, and consult IBM's security advisory (assigned by IBM PSIRT) for the fixed release or interim fix, then upgrade when IBM publishes one. Until patched, restrict authenticated access to DataStage and any RabbitMQ management interfaces to trusted personnel and monitor for unexpected queue or exchange deletions. Note that no public proof-of-concept or in-the-wild exploitation is currently known.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.