CVE-2026-42160
Received
Received - Intake
Insufficient Authorization in Data Space Portal for Pending Accounts
Publication date: 2026-05-08
Last updated on: 2026-05-11
Assigner: GitHub, Inc.
Description
Description
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered "PENDING" organization / user accounts. This issue has been patched in version 7.3.2.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sovity | dataspace-portal | From 2.1.1 (inc) to 7.3.2 (exc) |
| sovity | dataspace-portal | 7.3.2 |
| sovity | ds-portal-ce-backend | From 2.1.1 (inc) |
| sovity | ds-portal-ce-backend | 7.3.2 |
| sovity | frontend | 7.3.2 |
| sovity | catalog-crawler-ce | * |
| sovity | edc-ce | 16.5.0 |
| keycloak | keycloak | 26.4.7 |
| postgresql | postgresql | 17 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-602 | The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server. |
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |