Cross-site scripting in Talend Administration Center - #VU131258
Published: May 12, 2026
Talend Administration Center
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in Qlik Talend Administration Center when handling stored user-supplied content. A remote user can store an XSS payload to execute arbitrary script in a user's browser.
User interaction is required, and the payload is triggered when a different user accesses the stored content.