CVE-2026-6264 Details
Description
A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend JobServer by requiring TLS client authentication for the monitoring port; however, the patch must be applied for full mitigation. For Talend ESB Runtime, the vulnerability can be mitigated by disabling the JobServer JMX monitoring port, which is disabled by default from the R2024-07-RT patch.
A critical vulnerability allowing unauthenticated remote code execution has been identified in Talend JobServer versions prior to 8.0 (TPS-6017) and Talend Runtime versions prior to 8.0.1.R2026-01-RT or 7.3.1-R2026-01. The vulnerability arises from the JMX monitoring port, which can be exploited to execute arbitrary code on the server.
Users of Talend JobServer should upgrade to version 8.0 (TPS-6017) or 7.3 (TPS-6018). Talend Runtime users should upgrade to version 8.0.1.R2026-01-RT or 7.3.1-R2026-01.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/tac-p/2541974 | Bugcrowd Inc. |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Bugcrowd Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | New CVE Received | Bugcrowd Inc. |