Insufficient Authorization in Data Space Portal Software by Sovity
CVE-2026-42160

10CRITICAL

Key Information:

Vendor

Sovity

Vendor
CVE Published:
8 May 2026

What is CVE-2026-42160?

The Data Space Portal, an open-source SaaS solution for efficient dataspace management, is affected by a vulnerability due to insufficient authorization controls in the backend for self-registered 'PENDING' user accounts. This oversight allows unauthorized actions, potentially compromising the integrity and security of user data. The issue has been addressed in version 7.3.2, ensuring that proper checks are now in place to prevent unauthorized access.

Affected Version(s)

dataspace-portal >= 2.1.1, < 7.3.2

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.