CVE-2026-3053: DataLinkDC dinky OpenAPI Endpoint AppConfig.java addInterceptors missing authentication
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3053?
CVE-2026-3053 has been classified as a moderate severity vulnerability due to its potential impact on authentication processes.
How do I fix CVE-2026-3053?
To fix CVE-2026-3053, implement proper authentication checks in the addInterceptors function within the AppConfig.java file.
What software is affected by CVE-2026-3053?
CVE-2026-3053 affects DataLinkDC dinky versions up to and including 1.2.5.
What does CVE-2026-3053 exploit?
CVE-2026-3053 exploits missing authentication in the OpenAPI Endpoint's addInterceptors function.
Is there a known workaround for CVE-2026-3053?
A known workaround for CVE-2026-3053 includes manually reviewing and restricting access to sensitive endpoints until a proper patch is applied.