CVE-2026-9057
8.2Talend · Talend Administration Center
A broken access control vulnerability in Talend Administration Center allows users with "View" permissions to modify the Talend Studio update URL, potentially leading to unauthorized code execution.
Executive summary
A broken access control flaw in Talend Administration Center allows low-privileged users to modify update configurations, creating a vector for unauthorized software execution.
Vulnerability
This is an improper access control vulnerability (CWE-284) that allows a user with limited "View" permissions to alter critical update URL settings, which could be leveraged to point to malicious update repositories.
Business impact
The ability to manipulate update URLs can lead to the deployment of malicious software or unauthorized updates across the Talend environment, significantly impacting system integrity. With a CVSS score of 8.2 (High), this vulnerability presents a critical risk to the supply chain of the Talend Studio infrastructure.
Remediation
Immediate Action: Apply the specific security patch (Patch_20251121_QTAC-1471_R2025-11_v1-8.0.1) provided by the vendor to remediate this access control issue.
Proactive Monitoring: Audit the "Update URL" settings within the Administration Center to ensure they point to expected, legitimate Talend update servers.
Compensating Controls: Use network-level egress filtering to restrict the Administration Center from connecting to unauthorized or unknown update repositories.
Exploitation status
Public Exploit Available: false
Analyst recommendation
This vulnerability carries significant risk due to its potential for facilitating unauthorized code execution via modified update paths. Administrators should verify their current patch level and apply the referenced patch immediately to secure the Administration Center.