← Back

CVE-2026-25958

nvd nist
Published: Feb 9, 2026Modified: Jun 17, 2026

JSON object

Loading...
7.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Exploitability: 3.1 / Impact: 4.0
Source: security-advisories@github.com (Secondary)

Description

Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to privilege escalation. This vulnerability is fixed in 1.5.13, 1.4.2, and 1.0.14.

Affected (3)

Products: Cube: Cube.js
1 product
Cube.js
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Cube
From 0.27.19 to 1.0.14
From 1.1.0 to 1.4.2
From 1.5.0 to 1.5.13

References (1)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.