CVE-2025-59954: Knowage Contains a Remote Code Execution Vulnerability
Published Sep 29, 2025
·Updated
Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue is fixed in version 8.1.27.
Affected Software
2 affected components
Knowage Knowage<8.1.27
eng Knowage<8.1.27
Remediation
Event History
Sep 29, 2025
CVE Published
via MITRE·11:48 PM
Data Sourced
via MITRE·11:48 PM
DescriptionWeakness
Sep 30, 2025
Data Sourced
via NVD·11:37 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59954?
The severity of CVE-2025-59954 is classified as high due to the potential for remote code execution.
2
How do I fix CVE-2025-59954?
To fix CVE-2025-59954, upgrade Knowage to version 8.1.27 or later.
3
Which versions of Knowage are affected by CVE-2025-59954?
CVE-2025-59954 affects Knowage versions 8.1.26 and below.
4
What type of vulnerability is CVE-2025-59954?
CVE-2025-59954 is a remote code execution vulnerability.
5
Who should be concerned about CVE-2025-59954?
Organizations using affected versions of Knowage should be concerned about CVE-2025-59954 due to the risk of external exploitation.