CVE-2026-25644

DataHub · DataHub open-source metadata platform

A vulnerability in the DataHub open-source metadata platform could allow for unauthorized access to sensitive metadata or system functions.

Executive summary

The DataHub metadata platform is susceptible to a high-severity vulnerability that could lead to the compromise of critical metadata and unauthorized system access.

Vulnerability

This vulnerability is located within the DataHub platform, which serves as a central repository for an organization's metadata. With a CVSS score of 7.5, the flaw likely allows for unauthorized data access or manipulation, potentially due to an issue with authentication or authorization controls.

Business impact

A compromise of DataHub could lead to the exposure of sensitive information about an organization's data assets, including their location, structure, and ownership. The CVSS score of 7.5 reflects a high-severity risk to data governance and privacy. This could result in unauthorized data access across the entire organization and a significant breach of data security policies.

Remediation

Immediate Action: Apply the latest security patches for DataHub immediately. Ensure that the DataHub instance and all its components are updated to the most recent version.

Proactive Monitoring: Audit access logs for the DataHub platform to identify any unauthorized or suspicious metadata queries or modifications.

Compensating Controls: Implement strong authentication (e.g., OIDC, SAML) and role-based access control (RBAC) to restrict access to the DataHub platform to authorized personnel only.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Promptly updating the DataHub platform is essential for protecting the integrity and confidentiality of your organization's metadata. Given its role as a central data hub, a compromise here could have far-reaching consequences. Prioritize this update and review your data governance security practices.