Description
Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console.
Published: 2026-09-29
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Authenticated Input Injection
Action: Apply Patch
AI Analysis

Impact

An authenticated user can submit malicious data via the Tibco Administrator web console that the application fails to validate properly, creating an input injection flaw. This vulnerability may allow the attacker to alter system configuration, inject commands, or otherwise compromise the integrity of the administration environment. Because the flaw requires elevated privilege within the console, the attack vectors are limited to authenticated sessions, but the impact on confidentiality, integrity, and availability of the platform remains significant.

Affected Systems

Tibco Administrator versions 5.13.0 and earlier are affected. The advisory lists no additional versions, indicating that all builds prior to the published fix are vulnerable. Deployments that host the web‑based console, especially those exposed to external networks or integrated with other services, are therefore at risk.

Risk and Exploitability

The CVSS score of 8.7 places this flaw in the High severity range. Exploitation requires valid credentials, so attackers must either compromise a user account or obtain credentials by social engineering. The EPSS score is not available, but the lack of publicly reported exploits and the absence of a CISA KEV listing suggest that the present exploitation risk may be moderate. Nonetheless, the high severity combined with the authenticated nature warrants prompt remediation.

Generated by OpenCVE AI on September 29, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Tibco Administrator patch that addresses CVE-2026-4034.
  • Restrict access to the web console to trusted internal networks or use a bastion host, reducing exposure to unauthenticated users.
  • Enforce strong authentication mechanisms such as multi‑factor authentication to decrease the likelihood of credential compromise.

Generated by OpenCVE AI on September 29, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Tibco
Tibco administrator
Weaknesses CWE-79
Vendors & Products Tibco
Tibco administrator

Tue, 29 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-74
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console.
Title TIBCO Administrator Injection Vulnerability
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Tibco Administrator
cve-icon MITRE

Status: PUBLISHED

Assigner: tibco

Published:

Updated: 2026-09-29T14:33:25.093Z

Reserved: 2026-03-12T02:01:53.803Z

Link: CVE-2026-4034

cve-icon Vulnrichment

Updated: 2026-09-29T14:33:10.798Z

cve-icon NVD

Status : Received

Published: 2026-09-29T14:17:20.683

Modified: 2026-09-29T15:17:26.390

Link: CVE-2026-4034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:30:07Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')