A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions.

There is no workaround.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Knime
Knime business Hub
Vendors & Products Knime
Knime business Hub

Mon, 08 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Dec 2025 09:45:00 +0000

Type Values Removed Values Added
Description A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions. There is no workaround.
Title Jobs can be saved as workflows with wrong permissions on KNIME Business Hub
Weaknesses CWE-708
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Green'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: KNIME

Published:

Updated: 2025-12-08T17:19:30.677Z

Reserved: 2025-12-08T09:01:05.011Z

Link: CVE-2025-14262

cve-icon Vulnrichment

Updated: 2025-12-08T17:19:27.830Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-08T10:16:01.047

Modified: 2025-12-08T18:26:19.900

Link: CVE-2025-14262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-09T10:05:23Z

Weaknesses