CVE-2026-80434: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
Published Sep 7, 2026
·Updated
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
— MITRE
Affected Software
1 affected componentFixes available
IBM DataStage on Cloud Pak for Data<=5.4.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Sep 7, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 10, 2026
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need valid access to exploit this issue?
Yes. The issue requires a remote attacker to be authenticated to DataStage on Cloud Pak for Data.
2
What is the practical impact of successful exploitation?
An attacker could manipulate runtime caches, resulting in a denial of service.