Missing authentication for critical function in Talend JobServer and Talend Runtime - #VU122658
Published: February 11, 2026
Vulnerability identifier: #VU122658
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authentication checks in the JMX monitoring service. A remote non-authenticated attacker can send specially crafted packets to the server and execute arbitrary code on the system.
Affected software
Talend JobServer
Talend Runtime
Talend Runtime
Remediation
Install updates from vendor's website.
Talend JobServer - addressed in versions 7.3 TPS-6018, 8.0 TPS-6017
Talend Runtime - addressed in versions 7.3.1 R2026-01, 8.0.1 R2026-01-RT
Talend Runtime - addressed in versions 7.3.1 R2026-01, 8.0.1 R2026-01-RT