IBM DataStage on Cloud Pak for Data 5.4.0.0
IBM DataStage is a data integration tool that runs on IBM Cloud Pak for Data. A logged-in user with low-level access can exploit an authorization flaw to knock the service offline for other users.
- Severity
- HighCVSS 3.1 · 8.5
- Fix
- Fixed in 5.4 patch 5
- Affected versions
- 5.4.0
- Weakness
- CWE-285Improper Authorization
- Exploit likelihood
- 0.27% in 30 daysEPSS, higher than 19% of known flaws
- Affects
- DataStage on Cloud Pak for Data
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: partial
- EU ID
- EUVD-2026-75791ENISA vulnerability database
What to do
Check whether your organization runs DataStage on Cloud Pak for Data version 5.4.0.0. If it does, compare your deployment against IBM's security bulletin for this issue.
Upgrade DataStage on Cloud Pak for Data to 5.4 patch 5 or later. Follow IBM's patch instructions to apply the update. IBM states there is no workaround or mitigation other than upgrading.
Technical details
Affected software: DataStage on Cloud Pak for Databy IBM
CVE-2026-80378 is an improper authorization flaw (CWE-285) in DataStage on Cloud Pak for Data 5.4.0.0. A remote authenticated attacker with low privileges and no user interaction can trigger a denial of service, with CVSS 3.1 scope changed and high availability impact (score 8.5). IBM's bulletin lists no workaround, only an upgrade to 5.4 patch 5 or later.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact None No data disclosure
- Integrity impact Low Some data can be modified
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286562 vendor-advisory patch NVD
- tenable.com · CVE-2026-80378 third party advisory vdb entry
- cve.org · CVERecord vdb entry
- cvefeed.io · CVE-2026-80378 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-80378