Missing authentication for critical function in Talend JobServer and Talend Runtime - #VU122658

 

Missing authentication for critical function in Talend JobServer and Talend Runtime - #VU122658

Published: February 11, 2026


Vulnerability identifier: #VU122658
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authentication checks in the JMX monitoring service. A remote non-authenticated attacker can send specially crafted packets to the server and execute arbitrary code on the system. 


Affected software

Talend JobServer
Talend Runtime

Remediation

Install updates from vendor's website.

Talend JobServer - addressed in versions 7.3 TPS-6018, 8.0 TPS-6017
Talend Runtime - addressed in versions 7.3.1 R2026-01, 8.0.1 R2026-01-RT

External References

Related Security Bulletins