CVE-2026-42160
Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered "PENDING" organization / user accounts. This issue has been patched in version 7.3.2.
| CWE | CWE-602 CWE-863 |
| Vendor | sovity |
| Product | dataspace-portal |
| Published | May 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for sovity dataspace-portal
Be the first to know when new unknown vulnerabilities affecting sovity dataspace-portal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
sovity / dataspace-portal
>= 2.1.1, < 7.3.2