IBM DataStage on Cloud Pak for Data 5.4.0.0

Published September 10, 2026 CVE-2026-80378

IBM DataStage is a data integration tool that runs on IBM Cloud Pak for Data. A logged-in user with low-level access can exploit an authorization flaw to knock the service offline for other users.

Severity
HighCVSS 3.1 · 8.5
Fix
Fixed in 5.4 patch 5
Affected versions
5.4.0
Weakness
CWE-285Improper Authorization
Exploit likelihood
0.27% in 30 daysEPSS, higher than 19% of known flaws
Affects
DataStage on Cloud Pak for Data
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: partial
EU ID
EUVD-2026-75791ENISA vulnerability database

What to do

Check whether your organization runs DataStage on Cloud Pak for Data version 5.4.0.0. If it does, compare your deployment against IBM's security bulletin for this issue.

Upgrade DataStage on Cloud Pak for Data to 5.4 patch 5 or later. Follow IBM's patch instructions to apply the update. IBM states there is no workaround or mitigation other than upgrading.

Technical details

Affected software: DataStage on Cloud Pak for Databy IBM

CVE-2026-80378 is an improper authorization flaw (CWE-285) in DataStage on Cloud Pak for Data 5.4.0.0. A remote authenticated attacker with low privileges and no user interaction can trigger a denial of service, with CVSS 3.1 scope changed and high availability impact (score 8.5). IBM's bulletin lists no workaround, only an upgrade to 5.4 patch 5 or later.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact None No data disclosure
  • Integrity impact Low Some data can be modified
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H Open in FIRST.org calculator

References