In Grafana versions prior to 11.6.11, 12.0.9, 12.1.6, and 12.2.4 low severity vulnerability CVE-2026-21727 was detected. This vulnerability allows attackers with datasource management privileges to read and permanently delete legacy correlation data belonging to other organizations due to improper isolation of legacy records with org_id=0. To address this issue users must upgrade to 11.6.11, 12.0.9, 12.1.6, or 12.2.4 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21727.
Read more Data Analyticsp>In Apache Airflow versions 3.0.0 before 3.2.0 a medium severity vulnerability CVE-2026-32690 was detected. This vulnerability allows attackers to bypass secret redaction and view sensitive values stored in JSON dictionaries, as nested fields were not properly masked when retrieved with specific depth settings. To address this issue, users must upgrade to 3.2.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32690.
Read more Data AnalyticsIn Apache Airflow versions prior to 3.2.0 low severity vulnerability CVE-2025-54550 was detected. This vulnerability allows attackers to perform arbitrary execution of code on the worker if a UI user with XCom modification access exploits an unsafe reading pattern based on documentation examples. To address this issue users must upgrade to 3.2.0 version documentation standards and adjust their implementations accordingly. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-54550.
Read more Data AnalyticsIn Apache Cassandra versions 4.0, 4.1, and 5.0 medium severity vulnerability CVE-2026-32588 was detected. This vulnerability allows attackers to raise query latencies and cause a Denial of Service (DoS) via repeated password changes using the ALTER ROLE command. To address this issue users must upgrade to 4.0.20, 4.1.11, or 5.0.7 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-32588.
Read more DatabaseIn Apache Cassandra versions 4.0 medium severity vulnerability CVE-2026-27315 was detected. This vulnerability allows attackers to access sensitive information, such as cleartext passwords, by reading the cqlsh_history local file if they have access to the user’s home directory. To address this issue users must upgrade to 4.0.20 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27315.
Read more DatabaseIn Apache Cassandra versions 5.0 high severity vulnerability CVE-2026-27314 was detected. This vulnerability allows attackers with CREATE permissions to associate their certificate identity with an arbitrary role, including superuser roles, and authenticate as that role via the ADD IDENTITY command. To address this issue users must upgrade to 5.0.7+ version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27314.
Read more DatabaseIn Apache Airflow versions 3.0.0 before 3.2.0 medium severity vulnerability CVE-2025-57735 was detected. This vulnerability allows attackers to reuse a JWT token that was not properly invalidated after a user logged out, provided the token was intercepted. To address this issue users must upgrade to 3.2.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-57735.
Read more Data AnalyticsIn Zulip versions 1.4.0 to before 11.6 high severity vulnerability CVE-2026-25742 was detected. This vulnerability allows attackers to retrieve attachments originating from web-public streams and access topic history via the /users/me/<stream_id>/topics endpoint anonymously, even after spectator access has been disabled. To address this issue users must upgrade to 11.6 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25742.
Read more CommunicationIn Apache Airflow versions 3.0.0 through 3.1.8 high severity vulnerability CVE-2026-34538 was detected. This vulnerability allows attackers with low-privilege access (such as the Viewer role) to bypass authorization and retrieve sensitive XCom result values via the DagRun wait endpoint, which should be restricted under the FAB RBAC model. To address this issue users must upgrade to 3.2.0 version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34538.
Read more Data Analytics