Executive brief
A vulnerability exists in Spotfire Server, a platform used for data visualization and enterprise analytics. If exploited, this flaw could allow an attacker to compromise the integrity and confidentiality of the system, potentially leading to unauthorized data access or modification. The attack requires some level of user interaction to be successful.
Technical details
A vulnerability in the Spotfire Server modules of Spotfire Enterprise and Spotfire on Kubernetes allows for a high-impact compromise. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L) indicates a network-based attack vector that requires no special privileges but does require user interaction (UI:P). Successful exploitation results in high impacts to both confidentiality and integrity, with a low impact on availability. The vulnerability affects multiple versions of the Spotfire Server component across different deployment models.
Affected products
- Spotfire Spotfire Enterprise (Spotfire Server modules) through 14.0.12, 14.4.2, 14.5.0, 14.6.1, 14.6.2, 14.7.0, 14.8.0
- Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules) through 14.0.12, 14.5.0, 14.6.0, 14.6.1, 14.6.2, 14.7.0, 14.8.0
- Spotfire Spotfire on Kubernetes (Spotfire Server modules) through 4.2.0, 5.0.X, 6.0.X
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed