ZeroHour

CVE-2026-82107

niche

Improper Authentication in IBM DataStage on Cloud Pak for Data 5.4.0.0

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

IBM DataStage running on Cloud Pak for Data version 5.4.0.0 contains an improper authentication flaw (CWE-287) rated critical with a CVSS 3.1 score of 9.6. A remote attacker who already possesses valid low-privilege credentials can trigger the flaw over the network with no user interaction, exploiting a scope change to reach resources beyond the component's normal security boundary. Successful exploitation allows the attacker to obtain sensitive information and bypass security restrictions, causing high impact to both confidentiality and integrity, though availability is not affected. Organizations running self-managed IBM DataStage 5.4.0.0 on Cloud Pak for Data deployments are the affected population. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.

What to do: Upgrade IBM DataStage on Cloud Pak for Data 5.4.0.0 to the fixed release specified in IBM's security bulletin as soon as it is available, and verify any interim fixes IBM publishes. Restrict network access to DataStage service endpoints to trusted users and networks, and apply least-privilege role assignments since exploitation requires only low-privilege authenticated access. Review authentication and audit logs for anomalous authenticated activity and unexpected access to sensitive data.

Affected
IBM DataStage on Cloud Pak for Data5.4.0.0
Estimated exposure
nichelikely hundreds to low thousands of enterprise deployments worldwide (order of magnitude, estimated) — IBM DataStage is enterprise data-integration software deployed by large organizations on self-managed Cloud Pak for Data clusters, and no public install counts or internet-exposure scan data exist for this product, so this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

Vendors
ibm
Products
datastage on cloud pak for data
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.