IBM DataStage on Cloud Pak for Data 5.4.0.0

Published September 10, 2026 CVE-2026-80436

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

Severity
HighCVSS 3.1 · 8.5
Fix
Not confirmedLast checked today
Affected versions
5.4.0
Weakness
CWE-285Improper Authorization
Exploit likelihood
0.28% in 30 daysEPSS, higher than 20% of known flaws
Affects
DataStage on Cloud Pak for Data
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: partial
EU ID
EUVD-2026-75785ENISA vulnerability database

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact None No data disclosure
  • Integrity impact Low Some data can be modified
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H Open in FIRST.org calculator

References