Improper access control in Talend Administration Center - #VU131259
Published: May 12, 2026
Talend Administration Center
Detailed vulnerability description
The vulnerability allows a remote user to modify the Qlik Talend Studio update URL and cause the download of malicious software to a Qlik Talend Studio instance.
The vulnerability exists due to improper access control in the URL access control mechanism when handling requests to modify the Qlik Talend Studio update URL. A remote user can send a crafted request to modify the update URL and cause the download of malicious software to a Qlik Talend Studio instance.
The issue is exploitable by a user with View permission.