CVE-2026-11618: DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authentication
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Test Endpoint. Executing a manipulation can lead to improper authentication. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called f95389e7f74acec42bcee079a616aaa06f9551d2. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DTStack Taierto a version that resolves this vulnerability.Patch f95389e7f74acec42bcee079a616aaa06f9551d2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11618?
CVE-2026-11618 has a high severity rating of 7.3.
How do I fix CVE-2026-11618?
To mitigate CVE-2026-11618, it is recommended to update DTStack Taier to version 1.4.1 or later.
What type of vulnerability is CVE-2026-11618?
CVE-2026-11618 is an improper authentication vulnerability affecting the Source Connection Test Endpoint.
Who is affected by CVE-2026-11618?
Any user of DTStack Taier up to version 1.4.0 is potentially affected by CVE-2026-11618.
What can happen if CVE-2026-11618 is exploited?
Exploitation of CVE-2026-11618 could lead to unauthorized access to the Source Connection Test Endpoint.