<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T12:38:35.625056+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268267</id>
    <title>EUVD-2026-268267</title>
    <updated>2026-10-06T12:38:35.677126+00:00</updated>
    <content>EUVD-2026-268267</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26010</id>
    <title>fkie_cve-2026-26010</title>
    <updated>2026-10-06T12:38:35.677167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pqqf-7hxm-rj5r</id>
    <title>GHSA-pqqf-7hxm-rj5r — Leaky JWTs in OpenMetadata exposing highly-privileged bot users</title>
    <updated>2026-10-06T12:38:35.677201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.open-metadata:openmetadata-sdk</p>
<p>### Summary
Calls issued by the UI against `/api/v1/ingestionPipelines` leak JWTs used by `ingestion-bot` for certain services (Glue / Redshift / Postgres)</p>
<p>### Details
Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies).</p>
<p>### PoC
I was able to extract the JWT used by the bot/agent populating [sample_athena.default](https://sandbox.open-metadata.org/database/sample_athena.default) in the Collate Sandbox. To prove this out, I mutated the description to this UUID: `fe2e4cc1-da72-4acf-8535-112a3cfa9c7e,` which you can see  @ https://sandbox.open-metadata.org/database/sample_athena.default.</p>
<p>#### Steps to Reproduce</p>
<p>* Create a Collate Sandbox account; these are non-admin accounts by default with minimal permissions.
* Open the Developer Console
* Go to the Services Page. In this case, [sample_athena](https://sandbox.open-metadata.org/service/databaseServices/sample_athena?showDeletedTables=false&amp;currentPage=1), though other services 
* In the Network tab, introspect the request made to api/v1/services/ingestionPipelines, and find the jwtToken in the response:
&lt;img width="1329" height="299" alt="image" src="https://github.com/user-attachments/assets/0c405776-159e-4188-9591-ed8cc71bc596" /&gt;</p>
<p>* Use the JWT to issue (potentially destructive) API calls
&lt;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pqqf-7hxm-rj5r"/>
  </entry>
</feed>
