Junglewise Threat Intelligence

CVE-2026-9056: Qlik Talend Administration Center stored XSS in server management

CVE-2026-9056 · Severity: medium · CVSS 5.4 · Published 2026-05-20

Vendors: Qlik.

Executive brief

A security vulnerability exists in the Talend Administration Center, a management console used for administering data integration tasks. An authorized user with server management permissions can inject malicious scripts into the system. If another user views the affected area, these scripts could execute in their browser, potentially allowing the attacker to perform actions on their behalf or access sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the server management component of Qlik Talend Administration Center. The flaw is caused by insufficient input validation and output encoding of server configuration or management data. An attacker with low-privileged access (specifically 'permission to manage servers') can submit a malicious payload that is permanently stored on the server. When a different user, such as an administrator, interacts with the compromised interface, the payload executes in the context of their browser session. This can lead to session hijacking or unauthorized actions within the management console. The issue is resolved in Patch_20260123_QTAC-1883 for version 8.0.1.

Affected products

  • Qlik Talend Administration Center Before Patch_20260123_QTAC-1883 (v8.0.1)

Timeline

  • 2026-01-23: patched: Patch QTAC-1883 released
  • 2026-05-07: advisory: Qlik support article updated
  • 2026-05-20: disclosed: CVE-2026-9056 published to NVD

References

Related threats