CVE-2026-82107
nicheImproper Authentication in IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage running on Cloud Pak for Data version 5.4.0.0 contains an improper authentication flaw (CWE-287) rated critical with a CVSS 3.1 score of 9.6. A remote attacker who already possesses valid low-privilege credentials can trigger the flaw over the network with no user interaction, exploiting a scope change to reach resources beyond the component's normal security boundary. Successful exploitation allows the attacker to obtain sensitive information and bypass security restrictions, causing high impact to both confidentiality and integrity, though availability is not affected. Organizations running self-managed IBM DataStage 5.4.0.0 on Cloud Pak for Data deployments are the affected population. No public proof-of-concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.
What to do: Upgrade IBM DataStage on Cloud Pak for Data 5.4.0.0 to the fixed release specified in IBM's security bulletin as soon as it is available, and verify any interim fixes IBM publishes. Restrict network access to DataStage service endpoints to trusted users and networks, and apply least-privilege role assignments since exploitation requires only low-privilege authenticated access. Review authentication and audit logs for anomalous authenticated activity and unexpected access to sensitive data.
| IBM DataStage on Cloud Pak for Data | 5.4.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
- Vendors
- ibm
- Products
- datastage on cloud pak for data
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.