Stored cross-site scripting vulnerability in Talend Administration Center
CVE-2026-9056

5.4MEDIUM

Key Information:

Vendor

Talend

Vendor
CVE Published:
20 May 2026

What is CVE-2026-9056?

A stored cross-site scripting vulnerability has been identified in Talend Administration Center that allows an attacker with server management permissions to store a malicious XSS payload. This payload can be executed by other users of the system, posing significant risks including unauthorized access to sensitive data and potential account takeovers. It is crucial for organizations using the affected versions to apply security patches to mitigate these risks and protect user data.

Affected Version(s)

Talend Administration Center 8.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahsan
.