Description
A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file taier-data-develop/src/main/java/com/dtstack/taier/develop/interceptor/LoginInterceptor.java of the component Source Connection Test Endpoint. Executing a manipulation can lead to improper authentication. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. This patch is called f95389e7f74acec42bcee079a616aaa06f9551d2. A patch should be applied to remediate this issue.
Problem types
Product status
1.1
1.2
1.3
1.4.0
Timeline
| 2026-06-08: | Advisory disclosed |
| 2026-06-08: | VulDB entry created |
| 2026-06-08: | VulDB entry last update |
Credits
anch0r (VulDB User)
References
github.com/DTStack/Taier/issues/1194
vuldb.com/vuln/369299 (VDB-369299 | DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authentication)
vuldb.com/vuln/369299/cti (VDB-369299 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-11618 (CVE-2026-11618 | CVE Analysis and Report)
vuldb.com/submit/834008 (Submit #834008 | DTStack Taier <=1.0.0 Code Injection)
github.com/DTStack/Taier/issues/1194
github.com/...ommit/f95389e7f74acec42bcee079a616aaa06f9551d2
github.com/DTStack/Taier/