Junglewise Threat Intelligence

CVE-2026-80378: IBM DataStage denial of service via improper authorization

CVE-2026-80378 · Severity: high · CVSS 8.5 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data is a data integration and processing platform used within cloud environments. A remote authenticated attacker can cause the service to become unavailable by exploiting improper authorization checks, disrupting data pipeline operations for dependent business processes.

Technical details

This vulnerability in DataStage on Cloud Pak for Data 5.4.0.0 stems from improper authorization validation that allows an authenticated attacker to trigger a denial of service condition. The vulnerability requires network access and valid authentication credentials. An attacker can exploit insufficient access controls to perform actions that exhaust resources or crash the service. IBM has published a security bulletin documenting the issue and patching guidance.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats