Junglewise Threat Intelligence

CVE-2026-25958: Cube Core privilege escalation via specially crafted request

CVE-2026-25958 · Severity: low · CVSS 3.1 · Published 2026-02-10

Executive brief

Cube Core is a data analytics API server used to serve and manage complex data queries. An attacker with a valid API token can exploit a flaw in request validation to escalate privileges and gain unauthorized access to sensitive data. This could allow attackers with basic API access to read confidential information across tenants or business units.

Technical details

This privilege escalation vulnerability (CWE-807) exists in Cube Core versions ≥0.27.19 and is exploitable via a specially crafted request accompanied by a valid API token. The vulnerability stems from improper validation of user-controlled inputs in security decisions, allowing an authenticated attacker to bypass authorization controls. Exploitation requires network access and a valid API token (low privilege requirement), with no user interaction needed. A successful exploit permits high-confidence confidentiality breach (read access to protected data across security boundaries) with scope change. Patches are available: upgrade to version 1.5.13 (regular), 1.4.2 (LTS), or 1.0.14 (EOL LTS).

Affected products

  • Cube Cube Core >=0.27.19, <1.0.14; >=1.1.0, <1.4.2; >=1.5.0, <1.5.13

Timeline

  • 2026-02-10: disclosed
  • 2026-02-10: patched: Patches released for versions 1.5.13, 1.4.2, and 1.0.14

References

Related threats