Incorrect authorization in OpenMetadata - #VU151682
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain full administrator access.
The vulnerability exists due to incorrect authorization in the User PATCH handler and token-creation endpoint when processing root-level JSON Patch operations and impersonated token-creation requests. A remote attacker can promote a self-registered account to a bot and obtain an administrator personal access token.
Exploitation requires basic authentication with self-signup enabled.