HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-80412 — IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated a...

·Source: NIST NVD

Updated:

Executive Summary

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.

Analysis

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation. CVSS Score: 8.8. Published: 2026-09-23T21:17:03.067.

Indicators of Compromise (2)

CVE (1)
CVE-2026-80412
Source Attribution

Originally published by NIST NVD on Sep 23, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-86345 — A flaw was found in 389-ds-base. The server does not discard plaintext bytes alr...

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's own pending operation's response, due to messageID collision. This can cause a cl

CVE-2026-86345
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103765 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as tcp_data_port or re-create rpc_meta entries to redirect KV cache transfers to attacker-controlled listeners, or exhaust server

CVE-2026-103765
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103764 — Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference...

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory

CVE-2026-103764
NIST NVD