CVE-2026-25958Disclosure(cube / cube.js)

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to privilege escalation. This vulnerability is fixed in 1.5.13, 1.4.2, and 1.0.14.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-807

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cube.js

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-10)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
cube.js

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Technical Details · 2026-02-10: 202-0902-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-091
General1
2026-02-102
Disclosure2
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25958 Privilege Escalation Vulnerability in Cube Semantic Layer Across Multiple Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25958

    Post summary

    The entry announces a privilege escalation vulnerability in Cube Semantic Layer across multiple versions, but does not provide any PoC, exploit, patch, or active exploitation information.

    0001057
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25958 Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a v… https://www.cve.org/CVERecord?id=CVE-2026-25958

    Post summary

    The text briefly mentions CVE-2026-25958 as affecting Cube versions 0.27.19 through 1.5.13, noting that a specially crafted request may trigger the issue, but no further technical or exploit information is provided.

    00010188
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25958: The Cube Root of Chaos: Smuggling Admin Privileges via WebSocket Pollution Cube (formerly Cube.js) is the self-proclaimed 'semantic layer' for building data applications—a fancy way of saying it sits between your messy SQL databases an... https://cvereports.com/reports/CVE-2026-25958

    Post summary

    The text announces CVE-2026-25958, describing a privilege escalation attack via WebSocket pollution, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0000049
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcubecube.js-node.js-

Explore more