Insecure Direct Object Reference in IBM DataStage on Cloud Pak for Data
CVE-2026-80434

7.4HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
10 September 2026

What is CVE-2026-80434?

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is susceptible to an insecure direct object reference vulnerability that may allow a remote authenticated attacker to manipulate runtime caches. This manipulation could potentially lead to a denial of service, impacting the availability of the affected services. Users are advised to review the vendor's advisory for patches and mitigation strategies.

Affected Version(s)

DataStage on Cloud Pak for Data 5.4.0.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.