A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions.
There is no workaround.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.knime.com/security/advisories#CVE-2025-11239 |
|
History
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Knime
Knime business Hub |
|
| Vendors & Products |
Knime
Knime business Hub |
Mon, 08 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions. There is no workaround. | |
| Title | Jobs can be saved as workflows with wrong permissions on KNIME Business Hub | |
| Weaknesses | CWE-708 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: KNIME
Published: 2025-12-08T09:34:45.784Z
Updated: 2025-12-08T17:19:30.677Z
Reserved: 2025-12-08T09:01:05.011Z
Link: CVE-2025-14262
Updated: 2025-12-08T17:19:27.830Z
Status : Awaiting Analysis
Published: 2025-12-08T10:16:01.047
Modified: 2025-12-08T18:26:19.900
Link: CVE-2025-14262
No data.