Description
Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules).

This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X.
Published: 2026-07-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass has been identified in the OAuth2 implementation of Spotfire. The flaw enables a public OAuth client to obtain a valid authorization code and access token without performing the PKCE code verification that should be required for non‑confidential clients. This weakness removes an essential safeguard and provides a route for attackers to acquire authorized access to Spotfire data and services without providing a client secret or the required code challenge. The impact is that compromised data confidentiality, integrity, and availability can be affected depending on the permissions granted to the client.

Affected Systems

Spotfire Enterprise, Spotfire Enterprise with External Consumers, and Spotfire on Kubernetes are impacted. All versions from Spotfire Enterprise 14.0.12 up through 14.8.0, Spotfire Enterprise with External Consumers 14.0.12 through 14.8.0, and Spotfire on Kubernetes releases 4.2.0, 5.x, and 6.x contain the flaw.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 %, suggesting that exploitation is currently not widespread. It is not listed in the CISA KEV catalog. The attack likely involves initiating an OAuth flow from a public client, capturing the authorization code, and using it to request an access token without the expected PKCE validation. If successful, the attacker can obtain tokens with the client’s scopes and access protected Spotfire resources. No specific prerequisites are noted, so a user with the ability to launch the OAuth flow on a public client can potentially exploit the bypass.

Generated by OpenCVE AI on July 31, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spotfire Enterprise, Spotfire Enterprise with External Consumers, or Spotfire on Kubernetes to the latest patched release that addresses the PKCE bypass.
  • Re‑register any public OAuth clients and enforce the use of a proper PKCE code challenge method (e.g., S256) in their configuration.
  • Limit the use of public clients on the Spotfire platform and review OAuth client scopes to minimize potential impact if a bypass occurs.

Generated by OpenCVE AI on July 31, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Spotfire
Spotfire spotfire Enterprise
Spotfire spotfire Enterprise With External Consumers
Spotfire spotfire On Kubernetes
Vendors & Products Spotfire
Spotfire spotfire Enterprise
Spotfire spotfire Enterprise With External Consumers
Spotfire spotfire On Kubernetes

Sun, 26 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Thu, 23 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X.
Title Spotfire OAuth2 PKCE Bypass for public clients
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Spotfire Spotfire Enterprise Spotfire Enterprise With External Consumers Spotfire On Kubernetes
cve-icon MITRE

Status: PUBLISHED

Assigner: Spotfire

Published:

Updated: 2026-07-14T15:02:35.187Z

Reserved: 2026-05-14T08:09:31.186Z

Link: CVE-2026-8590

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses