Junglewise Threat Intelligence

CVE-2026-80436: IBM DataStage on Cloud Pak for Data improper authorization in RabbitMQ

CVE-2026-80436 · Severity: high · CVSS 8.5 · Published 2026-09-10

Technologies: IBM Datastage On Cloud Pak For Data. Vendors: IBM.

Executive brief

IBM DataStage on Cloud Pak for Data is a data integration and ETL platform used for enterprise data processing and workflows. A remote authenticated attacker can delete arbitrary RabbitMQ queues or exchanges due to improper authorization checks, causing denial of service to data pipelines and messaging infrastructure that depend on these queues for operation.

Technical details

The vulnerability exists in IBM DataStage on Cloud Pak for Data 5.4.0.0 due to improper authorization controls around RabbitMQ queue and exchange management. An authenticated attacker with network access to the DataStage service can exploit this flaw to delete arbitrary RabbitMQ queues or exchanges, even if they lack the permissions required to perform such operations. The attack requires valid authentication credentials but does not require elevated privileges or user interaction. Exploitation results in denial of service by disrupting message queuing infrastructure relied upon by DataStage jobs and workflows. A patch or update addressing the authorization check is expected from IBM.

Affected products

  • IBM DataStage on Cloud Pak for Data 5.4.0.0

Timeline

  • 2026-09-10: disclosed

References

Related threats