CVE-2026-26010Disclosure(open-metadata / openmetadata)

LOWCVSS 7.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch open-metadata openmetadata systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openmetadata

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
openmetadata

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Mentions · 2026-02-17: 1PoC Mentioned / Linked · 2026-02-17: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 102-1102-1202-17
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-121
Disclosure1
2026-02-171
PoC1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26010 OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain se… https://www.cve.org/CVERecord?id=CVE-2026-26010

    Post summary

    CVE-2026-26010 exposes a JWT leakage in OpenMetadata UI API calls for versions before 1.11.8, potentially exposing authentication tokens.

    00030307
    56.5K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️#OpenMetadata: disponibile un #PoC per lo sfruttamento della CVE-2026-26010 Rischio:🟠 Tipologia: 🔸Information Disclosure 🔸Privilege escalation 🔗https://www.acn.gov.it/portale/en/csirt-italia/alert-e-bollettini?tipologia=39682 ⚠ Ove non provveduto, si raccomanda l’aggiornamento del software… https://t.co/Qwy0x3Ds1E

    Post summary

    A Proof of Concept for CVE-2026-26010 is available and the alert recommends updating the software; no evidence of active exploitation or detailed exploit code is provided.

    0000084
    607 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26010: OpenMetadata's Open Kimono: CVE-2026-26010 Leaks the Keys to the Kingdom A critical information disclosure vulnerability in OpenMetadata's REST API allowed authenticated users with minimal privileges to retrieve the raw JWT tokens of t... https://cvereports.com/reports/CVE-2026-26010

    Post summary

    The text announces a critical information disclosure in OpenMetadata’s REST API that lets low-privilege authenticated users retrieve raw JWT tokens, with no indication of exploitation, PoC, or patch.

    0000051
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen-metadataopenmetadata---

Explore more