CVE-2026-80436: DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
DataStage on Cloud Pak for Data could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
Other sources
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataStage on Cloud Pak for Datato a version that resolves this vulnerability.Fixed in 5.4 patch 5 or later
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated to DataStage on Cloud Pak for Data. The described impact is denial of service through deletion of arbitrary RabbitMQ queues or exchanges.
What authorization weakness is involved?
The issue is caused by improper authorization. An authenticated attacker may be able to delete RabbitMQ queues or exchanges that they should not be permitted to manage.