← back
CVE-2026-11618

DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authentication

CVSS 6.9 MEDIUMEPSS 0.4%CWE-287
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.4%KEV nãoPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
09 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Test Endpoint. Executing a manipulation can lead to improper authentication. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called f95389e7f74acec42bcee079a616aaa06f9551d2. A patch should be applied to remediate this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
DTStack · Taier
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.