Junglewise Threat Intelligence

CVE-2026-80434: IBM DataStage insecure direct object reference denial of service

CVE-2026-80434 · Severity: high · CVSS 7.4 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage is a data integration tool used within Cloud Pak for Data to manage data pipelines and transformations. A remote authenticated attacker can manipulate runtime caches through an insecure direct object reference vulnerability, causing the service to become unavailable and disrupting data processing operations.

Technical details

The vulnerability is an insecure direct object reference (IDOR) in IBM DataStage on Cloud Pak for Data 5.4.0.0 that allows a remote authenticated attacker to manipulate runtime caches without proper authorization checks. The attack requires valid authentication credentials but can be executed over the network without user interaction. By exploiting this IDOR, an attacker can trigger a denial of service condition, making the DataStage service unavailable. The vulnerability affects the caching mechanisms that DataStage relies on for runtime operations.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats