🔐 CVE Alert

CVE-2026-9057

HIGH 8.2

Security fix for Qlik Talend Administration Center URL access control vulnerability

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available.

Vendor talend
Product talend administration center
Published May 20, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for talend talend administration center

Be the first to know when new high vulnerabilities affecting talend talend administration center are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Talend / Talend Administration Center
8.0 < Patch_20251121_QTAC-1471_R2025-11_v1-8.0.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
community.qlik.com: https://community.qlik.com/t5/Official-Support-Articles/Security-fix-for-Qlik-Talend-Administration-Center-URL-access/ta-p/2548524

Credits

Kaushik Roy