OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Feb 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 12 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-metadata
Open-metadata openmetadata |
|
| Vendors & Products |
Open-metadata
Open-metadata openmetadata |
Wed, 11 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8. | |
| Title | Leaky JWTs in OpenMetadata exposing highly-privileged bot users | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-11T21:05:38.735Z
Updated: 2026-02-12T21:22:40.311Z
Reserved: 2026-02-09T21:36:29.553Z
Link: CVE-2026-26010
Updated: 2026-02-12T21:22:36.892Z
Status : Analyzed
Published: 2026-02-11T21:16:21.117
Modified: 2026-02-13T21:34:48.030
Link: CVE-2026-26010
No data.