Executive brief
A security flaw in the Talend Administration Center allows users with limited 'View' permissions to change the update URL for Talend Studio. This could allow an attacker to redirect software updates to a malicious server, potentially leading to the installation of unauthorized or harmful software on developer workstations. Organizations using this platform should apply the available security patch to prevent unauthorized configuration changes.
Technical details
A broken access control vulnerability exists in the Talend Administration Center (TAC) due to improper permission enforcement. An authenticated attacker with low-level 'View' privileges can bypass intended restrictions to modify the Talend Studio update URL configuration. By redirecting this URL to a server under their control, the attacker could facilitate the delivery of malicious updates to Talend Studio instances. The attack requires network access to the TAC interface and valid low-privileged credentials. A patch (QTAC-1471) has been released to address this issue by enforcing proper authorization checks.
Affected products
- Qlik Talend Administration Center All versions before Patch_20251121_QTAC-1471_R2025-11_v1-8.0.1
Timeline
- 2025-11-21: patched: Patch QTAC-1471 released
- 2026-05-20: disclosed: CVE-2026-9057 published