Insufficient Authorization in Data Space Portal Software by Sovity
CVE-2026-42160
10CRITICAL
What is CVE-2026-42160?
The Data Space Portal, an open-source SaaS solution for efficient dataspace management, is affected by a vulnerability due to insufficient authorization controls in the backend for self-registered 'PENDING' user accounts. This oversight allows unauthorized actions, potentially compromising the integrity and security of user data. The issue has been addressed in version 7.3.2, ensuring that proper checks are now in place to prevent unauthorized access.
Affected Version(s)
dataspace-portal >= 2.1.1, < 7.3.2
