CVE-2026-9056
Deferred Deferred - Pending Action
Stored XSS in Talend Administration Center

Publication date: 2026-05-20

Last updated on: 2026-05-20

Assigner: Bugcrowd Inc.

Description
A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-20
Last Modified
2026-05-20
Generated
2026-06-09
AI Q&A
2026-05-20
EPSS Evaluated
2026-06-08
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
qlik talend_administration_center *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) issue found in the Talend Administration Center. It allows an attacker who has permission to manage servers to store malicious scripts within the system.

These malicious scripts can then be triggered by other users when they interact with the affected system, potentially leading to unauthorized actions or data exposure.

Impact Analysis

The vulnerability can impact you by allowing attackers with server management permissions to inject malicious scripts that execute in the context of other users.

This can lead to unauthorized access to sensitive information, manipulation of user sessions, or other malicious activities that compromise the integrity and confidentiality of the system.

Mitigation Strategies

To mitigate the stored cross-site scripting vulnerability in the Qlik Talend Administration Center, users should upgrade to the latest version of the software.

Specifically, installing the cumulative patch QTAC-1883, released on January 23, 2026, addresses this vulnerability.

No further updates are required beyond installing this patch.

Compliance Impact

The stored cross-site scripting (XSS) vulnerability in the Talend Administration Center allows attackers with server management permissions to inject malicious scripts that can be triggered by other users. Such vulnerabilities can potentially lead to unauthorized access or exposure of sensitive data, which may impact compliance with data protection regulations like GDPR and HIPAA that require safeguarding personal and sensitive information.

Mitigating this vulnerability by applying the provided patch is essential to maintain compliance, as failure to address security flaws that could lead to data breaches might result in regulatory penalties.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9056. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart