A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions. There is no workaround.
History

Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Knime
Knime business Hub
Vendors & Products Knime
Knime business Hub

Mon, 08 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Dec 2025 09:45:00 +0000

Type Values Removed Values Added
Description A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions. There is no workaround.
Title Jobs can be saved as workflows with wrong permissions on KNIME Business Hub
Weaknesses CWE-708
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: KNIME

Published: 2025-12-08T09:34:45.784Z

Updated: 2025-12-08T17:19:30.677Z

Reserved: 2025-12-08T09:01:05.011Z

Link: CVE-2025-14262

cve-icon Vulnrichment

Updated: 2025-12-08T17:19:27.830Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-08T10:16:01.047

Modified: 2025-12-08T18:26:19.900

Link: CVE-2025-14262

cve-icon Redhat

No data.