Description
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
Published: 2026-09-10
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access and security bypass via authentication failure
Action: Immediate patch
AI Analysis

Impact

This vulnerability arises from improper authentication handling in IBM DataStage on Cloud Pak for flaw to retrieve sensitive weakness is an authentication failure (CWE-287) that allows attackers to gain elevated access beyond what is intended by the system.

Affected Systems

It affects IBM DataStage on Cloud Pak for Data version 5.4.0.0 installed in Cloud Pak environments. The official advisory recommends that any deployments running this version be upgraded.

Risk and Exploitability

The CVSS score of 9.6 marks this as a critical vulnerability, and while the EPSS score is not available, the lack of KEV listing does not diminish the risk of exploitation. The likely attack vector is remote, authenticated access, meaning an adversary with valid credentials can leverage the flaw from any network location that can reach the application.

Generated by OpenCVE AI on September 11, 2026 at 04:34 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading DataStage on Cloud Pak for Data. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsDataStage on Cloud Pak for Data5.4.0.0 Upgrade to 5.4 patch 5 or later by following these instructions https://www.ibm.com/docs/en/software-hub/5.4.x .


OpenCVE Recommended Actions

  • Upgrade DataStage on Cloud Pak for Data to patch 5 or later following IBM’s instructions
  • Replace any default or weak administrative credentials with strong, unique passwords
  • Restrict user permissions to the minimum required roles and monitor for unauthorized activity

Generated by OpenCVE AI on September 11, 2026 at 04:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0:*:*:*:*:*:*:*

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
Title DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
First Time appeared Ibm
Ibm datastage On Cloud Pak For Data
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm datastage On Cloud Pak For Data
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Ibm Datastage On Cloud Pak For Data
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T13:46:25.007Z

Reserved: 2026-08-28T05:10:24.598Z

Link: CVE-2026-82107

cve-icon Vulnrichment

Updated: 2026-09-11T13:39:18.887Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:04.220

Modified: 2026-09-16T00:37:55.033

Link: CVE-2026-82107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:30:11Z

Weaknesses