CVE-2026-11618 Details
Description
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Test Endpoint. Executing a manipulation can lead to improper authentication. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called f95389e7f74acec42bcee079a616aaa06f9551d2. A patch should be applied to remediate this issue.
An authentication bypass vulnerability has been identified in DTStack Taier versions through 1.4.0. The issue resides in the LoginInterceptor component, specifically within the preHandle function. This vulnerability allows unauthenticated users to execute arbitrary code on the server with root privileges. The exploitation process involves bypassing authentication, injecting malicious JDBC URLs, and leveraging vulnerable PostgreSQL JDBC driver versions to execute commands remotely.
Users are advised to upgrade to DTStack Taier versions after 1.4.0, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 9, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DTStack/Taier/issues/1194 | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/DTStack/Taier/ | [email protected] | Vendor |
| https://github.com/DTStack/Taier/commit/f95389e7f74acec42bcee079a616aaa06f9551d2 | [email protected] | Source CodeVendor |
| https://github.com/DTStack/Taier/issues/1194 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-11618 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/834008 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/369299 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/369299/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DTStack Taier | <= 1.4.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | New CVE Received | [email protected] |
Volerion