CVE-2026-8590
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in TIBCO Spotfire Server

Vulnerability report for CVE-2026-8590, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: 8b479ca1-d558-42a2-87eb-a4751ba58a09

Description

Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
spotfire spotfire_enterprise to 14.8.0 (exc)
spotfire spotfire_enterprise_with_external_consumers to 14.8.0 (exc)
spotfire spotfire_on_kubernetes to 4.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-8590 is a vulnerability affecting multiple versions of Spotfire products, including Spotfire Enterprise, Spotfire Enterprise with External Consumers, and Spotfire on Kubernetes. The issue resides in the Spotfire Server modules of these products.

The vulnerability impacts a broad range of versions: Spotfire Enterprise up to 14.0.12, 14.4.2, 14.5.0, 14.6.1, 14.6.2, 14.7.0, and 14.8.0; Spotfire Enterprise with External Consumers up to 14.0.12, 14.5.0, 14.6.0, 14.6.1, 14.6.2, 14.7.0, and 14.8.0; and Spotfire on Kubernetes up to 4.2.0, 5.0.X, and 6.0.X.

The CVSS v4.0 base score for this vulnerability is 8.7, indicating a high severity. The vector AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L suggests it is exploitable over a network with low attack complexity, no privileges required, and user interaction is needed. It can lead to high impacts on confidentiality and integrity, with a low impact on availability.

Detection Guidance

I don't know

The provided context does not include specific detection methods or commands for identifying this vulnerability on a network or system. Detection typically involves checking the installed version of Spotfire Enterprise, Spotfire Enterprise with External Consumers, or Spotfire on Kubernetes against the affected versions listed in the description.

Impact Analysis

If you are using an affected version of Spotfire Enterprise, Spotfire Enterprise with External Consumers, or Spotfire on Kubernetes, this vulnerability could have several impacts.

  • An attacker could exploit this vulnerability over a network without needing any special privileges, potentially leading to unauthorized access to sensitive data.
  • The high impact on confidentiality and integrity means that an attacker could view, modify, or delete sensitive information stored or processed by the affected Spotfire products.
  • Although the availability impact is low, there is still a risk of partial disruption to services relying on the affected Spotfire modules.

User interaction is required for exploitation, meaning an attacker would likely need to trick a user into performing an action, such as clicking a malicious link or opening a crafted file.

Compliance Impact

This vulnerability could have significant implications for compliance with common data protection and privacy regulations.

  • GDPR: If the affected Spotfire products process personal data of EU citizens, a breach resulting from this vulnerability could lead to unauthorized access or disclosure of personal data. This may violate GDPR requirements for data protection and could result in substantial fines or legal action.
  • HIPAA: For organizations handling protected health information (PHI) in the U.S., exploitation of this vulnerability could lead to unauthorized access or alteration of PHI. This would constitute a breach under HIPAA, potentially resulting in penalties and mandatory breach notifications.
  • Other standards: Depending on the industry, this vulnerability could also impact compliance with standards like PCI DSS (if payment data is involved) or sector-specific regulations that mandate strong data protection controls.

Organizations using affected versions of Spotfire should assess their exposure and take remediation steps to avoid potential compliance violations.

Mitigation Strategies

To mitigate this vulnerability, follow these steps:

  • Upgrade Spotfire Enterprise to a version later than 14.0.12, 14.4.2, 14.5.0, 14.6.1, 14.6.2, 14.7.0, or 14.8.0, depending on your current version.
  • Upgrade Spotfire Enterprise with External Consumers to a version later than 14.0.12, 14.5.0, 14.6.0, 14.6.1, 14.6.2, 14.7.0, or 14.8.0, depending on your current version.
  • Upgrade Spotfire on Kubernetes to a version later than 4.2.0, 5.0.X, or 6.0.X, depending on your current version.

If upgrading is not immediately possible, consider implementing network-level controls to restrict access to the affected Spotfire Server modules until patches can be applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8590. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart