<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 00:52:57 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-268267</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-268267</link>
      <description>EUVD-2026-268267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-268267</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26010</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26010</link>
      <description>&lt;p&gt;OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26010</guid>
    </item>
    <item>
      <title>GHSA-pqqf-7hxm-rj5r — Leaky JWTs in OpenMetadata exposing highly-privileged bot users</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pqqf-7hxm-rj5r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.open-metadata:openmetadata-sdk&lt;/p&gt;
&lt;p&gt;### Summary
Calls issued by the UI against `/api/v1/ingestionPipelines` leak JWTs used by `ingestion-bot` for certain services (Glue / Redshift / Postgres)&lt;/p&gt;
&lt;p&gt;### Details
Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies).&lt;/p&gt;
&lt;p&gt;### PoC
I was able to extract the JWT used by the bot/agent populating [sample_athena.default](https://sandbox.open-metadata.org/database/sample_athena.default) in the Collate Sandbox. To prove this out, I mutated the description to this UUID: `fe2e4cc1-da72-4acf-8535-112a3cfa9c7e,` which you can see  @ https://sandbox.open-metadata.org/database/sample_athena.default.&lt;/p&gt;
&lt;p&gt;#### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;* Create a Collate Sandbox account; these are non-admin accounts by default with minimal permissions.
* Open the Developer Console
* Go to the Services Page. In this case, [sample_athena](https://sandbox.open-metadata.org/service/databaseServices/sample_athena?showDeletedTables=false&amp;amp;currentPage=1), though other services 
* In the Network tab, introspect the request made to api/v1/services/ingestionPipelines, and find the jwtToken in the response:
&amp;lt;img width=&amp;#34;1329&amp;#34; height=&amp;#34;299&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/0c405776-159e-4188-9591-ed8cc71bc596&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;* Use the JWT to issue (potentially destructive) API calls
&amp;lt;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.open-metadata:openmetadata-sdk&lt;/p&gt;
&lt;p&gt;### Summary
Calls issued by the UI against `/api/v1/ingestionPipelines` leak JWTs used by `ingestion-bot` for certain services (Glue / Redshift / Postgres)&lt;/p&gt;
&lt;p&gt;### Details
Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies).&lt;/p&gt;
&lt;p&gt;### PoC
I was able to extract the JWT used by the bot/agent populating [sample_athena.default](https://sandbox.open-metadata.org/database/sample_athena.default) in the Collate Sandbox. To prove this out, I mutated the description to this UUID: `fe2e4cc1-da72-4acf-8535-112a3cfa9c7e,` which you can see  @ https://sandbox.open-metadata.org/database/sample_athena.default.&lt;/p&gt;
&lt;p&gt;#### Steps to Reproduce&lt;/p&gt;
&lt;p&gt;* Create a Collate Sandbox account; these are non-admin accounts by default with minimal permissions.
* Open the Developer Console
* Go to the Services Page. In this case, [sample_athena](https://sandbox.open-metadata.org/service/databaseServices/sample_athena?showDeletedTables=false&amp;amp;currentPage=1), though other services 
* In the Network tab, introspect the request made to api/v1/services/ingestionPipelines, and find the jwtToken in the response:
&amp;lt;img width=&amp;#34;1329&amp;#34; height=&amp;#34;299&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/0c405776-159e-4188-9591-ed8cc71bc596&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;* Use the JWT to issue (potentially destructive) API calls
&amp;lt;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pqqf-7hxm-rj5r</guid>
    </item>
  </channel>
</rss>
