A critical improper authentication flaw in IBM DataStage on Cloud Pak for Data 5.4.0.0 lets a remote authenticated attacker read sensitive information and bypass security restrictions across a trust boundary. The issue is tracked as CVE-2026-82107 with a CVSS score of 9.6.
What Is It
CVE-2026-82107 is an improper authentication vulnerability (CWE-287) in IBM DataStage on Cloud Pak for Data 5.4.0.0, disclosed by IBM PSIRT on 2026-09-10. Per IBM's description, the flaw "could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication."
IBM assigned a CVSS 3.1 base score of 9.6 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N: network attack vector, low attack complexity, low privileges required, no user interaction, changed scope, high confidentiality and integrity impact, no availability impact.
Why It Matters
The score is driven by two things: the low bar to attack and the changed scope. An attacker needs only low-privilege credentials (any legitimate account is enough) and no user interaction, over the network, at low complexity. The changed-scope flag means the impact does not stay inside the vulnerable component; the authentication bypass reaches resources beyond it.
DataStage is a data integration platform, so the confidentiality and integrity impact both rated HIGH is significant: the data moving through it is typically aggregated from across an enterprise. Availability is unaffected, which fits an access-control failure rather than a crash condition.
The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog in the supplied source material, so there is no confirmation of active exploitation at this time.
What's Vulnerable
- Vendor: IBM
- Product: DataStage on Cloud Pak for Data
- Affected version: 5.4.0.0 (
cpe:2.3:a:ibm:datastage_on_cloud_pak_for_data:5.4.0.0:*:*:*:*:*:*:*)
No other versions are identified as affected in the supplied record.
Patch Status
The NVD record is in Received status as of 2026-09-10 and has not yet been analyzed. IBM has published a support bulletin (node 7286562) as the sole reference; administrators should consult it directly for fixed versions and remediation steps. No CISA KEV entry exists in the supplied data, so no federally mandated remediation due date applies.
Sources
- NVD, CVE-2026-82107: https://nvd.nist.gov/vuln/detail/CVE-2026-82107
- IBM Support Bulletin ([email protected]): https://www.ibm.com/support/pages/node/7286562