<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Critical Security fix for the Qlik Talend JobServer and Talend Runtime (CVE-2026-6264) in Official Support Articles</title>
    <link>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/ta-p/2541970</link>
    <description>&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Executive Summary&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;A critical security issue in the &lt;FONT color="#339966"&gt;&lt;STRONG&gt;Talend JobServer&lt;/STRONG&gt;&lt;/FONT&gt; and &lt;STRONG&gt;&lt;FONT color="#339966"&gt;Talend Runtime&lt;/FONT&gt;&lt;/STRONG&gt; has been identified. This issue was resolved in later patches, which are already available. If the vulnerability is successfully exploited, an attacker could gain full remote code execution on the Talend JobServer and Talend Runtime servers.&lt;/P&gt;
&lt;P&gt;This issue was discovered by Harpreet Singh (@TheCyb3rAlphaProfession), Security Researcher.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Affected Software&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;All versions of Talend JobServer before TPS-6017 (8.0) or TPS-6018 (7.3).&lt;/LI&gt;
&lt;LI&gt;All versions of Talend Runtime before 8.0.1.R2026-01-RT or 7.3.1-R2026-01&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity Rating&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Using the CVSS V3.1 scoring system (&lt;A href="https://nvd.nist.gov/vuln-metrics/cvss" target="_blank" rel="noopener"&gt;https://nvd.nist.gov/vuln-metrics/cvss&lt;/A&gt;), this issue is rated CRITICAL.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Vulnerability Details&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P data-unlink="true"&gt;CVE-&lt;SPAN data-teams="true"&gt;2026-6264&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&lt;/FONT&gt; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (&lt;STRONG&gt;9.8 Critical&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;A critical vulnerability has been found in the Talend JobServer and Talend Runtime that allows unauthenticated remote code execution&lt;/P&gt;
&lt;P&gt;The attack vector for this vulnerability is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend Jobserver by requiring TLS client authentication for the monitoring port. However, the patch will need to be applied to fully mitigate the vulnerability. &lt;BR /&gt;For Talend Runtime, the vulnerability can be mitigated by disabling the JobServer JMX monitoring port, which is disabled by default from the 8.0 R2024-07-RT patch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Recommendation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P data-unlink="true"&gt;Upgrade at the earliest. The following table lists the patch versions addressing the vulnerability (CVE-&lt;SPAN data-teams="true"&gt;2026-6264&lt;/SPAN&gt;).&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;Always update to the latest version. Before you upgrade, check if a more recent release is available.&lt;/BLOCKQUOTE&gt;
&lt;TABLE style="width: 100%;" border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="background-color: lightgray; width: 29.9921%;"&gt;&amp;nbsp;&lt;STRONG&gt;Product&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: lightgray; width: 19.9815%;"&gt;&lt;STRONG&gt;Patch&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: lightgray; width: 19.9815%;"&gt;&lt;STRONG&gt;Release Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 29.9921%;"&gt;Talend JobServer 8.0&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;&lt;A href="https://help.qlik.com/talend/en-US/patch-notes/8.0/tps-6017" target="_blank" rel="noopener"&gt;TPS-6017&lt;/A&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;January 16, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="width: 29.9921%;"&gt;Talend Jobserver 7.3&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="width: 19.9815%;"&gt;TPS-6018&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="width: 19.9815%;"&gt;January 16, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 29.9921%;"&gt;Talend Runtime 8.0&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;&lt;A href="https://help.qlik.com/talend/en-US/patch-notes/8.0/r2026-01-rt" target="_blank" rel="noopener"&gt;8.0.1.R2026-01-RT&lt;/A&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;January 24, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="24px" style="width: 29.9921%;"&gt;Talend Runtime 7.3&lt;/TD&gt;
&lt;TD height="24px" style="width: 19.9815%;"&gt;7.3.1-R2026-01&lt;/TD&gt;
&lt;TD height="24px" style="width: 19.9815%;"&gt;January 24, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Wed, 15 Apr 2026 08:52:30 GMT</pubDate>
    <dc:creator>Sonja_Bauernfeind</dc:creator>
    <dc:date>2026-04-15T08:52:30Z</dc:date>
    <item>
      <title>Critical Security fix for the Qlik Talend JobServer and Talend Runtime (CVE-2026-6264)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/ta-p/2541970</link>
      <description>&lt;H3&gt;&lt;STRONG&gt;&lt;FONT color="#339966"&gt;Executive Summary&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;A critical security issue in the &lt;FONT color="#339966"&gt;&lt;STRONG&gt;Talend JobServer&lt;/STRONG&gt;&lt;/FONT&gt; and &lt;STRONG&gt;&lt;FONT color="#339966"&gt;Talend Runtime&lt;/FONT&gt;&lt;/STRONG&gt; has been identified. This issue was resolved in later patches, which are already available. If the vulnerability is successfully exploited, an attacker could gain full remote code execution on the Talend JobServer and Talend Runtime servers.&lt;/P&gt;
&lt;P&gt;This issue was discovered by Harpreet Singh (@TheCyb3rAlphaProfession), Security Researcher.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Affected Software&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;All versions of Talend JobServer before TPS-6017 (8.0) or TPS-6018 (7.3).&lt;/LI&gt;
&lt;LI&gt;All versions of Talend Runtime before 8.0.1.R2026-01-RT or 7.3.1-R2026-01&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity Rating&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P&gt;Using the CVSS V3.1 scoring system (&lt;A href="https://nvd.nist.gov/vuln-metrics/cvss" target="_blank" rel="noopener"&gt;https://nvd.nist.gov/vuln-metrics/cvss&lt;/A&gt;), this issue is rated CRITICAL.&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Vulnerability Details&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;P data-unlink="true"&gt;CVE-&lt;SPAN data-teams="true"&gt;2026-6264&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt;&lt;/FONT&gt; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (&lt;STRONG&gt;9.8 Critical&lt;/STRONG&gt;)&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;A critical vulnerability has been found in the Talend JobServer and Talend Runtime that allows unauthenticated remote code execution&lt;/P&gt;
&lt;P&gt;The attack vector for this vulnerability is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend Jobserver by requiring TLS client authentication for the monitoring port. However, the patch will need to be applied to fully mitigate the vulnerability. &lt;BR /&gt;For Talend Runtime, the vulnerability can be mitigated by disabling the JobServer JMX monitoring port, which is disabled by default from the 8.0 R2024-07-RT patch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H3&gt;
&lt;H4&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;Recommendation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H4&gt;
&lt;P data-unlink="true"&gt;Upgrade at the earliest. The following table lists the patch versions addressing the vulnerability (CVE-&lt;SPAN data-teams="true"&gt;2026-6264&lt;/SPAN&gt;).&lt;/P&gt;
&lt;BLOCKQUOTE class="quote"&gt;Always update to the latest version. Before you upgrade, check if a more recent release is available.&lt;/BLOCKQUOTE&gt;
&lt;TABLE style="width: 100%;" border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="background-color: lightgray; width: 29.9921%;"&gt;&amp;nbsp;&lt;STRONG&gt;Product&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: lightgray; width: 19.9815%;"&gt;&lt;STRONG&gt;Patch&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: lightgray; width: 19.9815%;"&gt;&lt;STRONG&gt;Release Date&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 29.9921%;"&gt;Talend JobServer 8.0&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;&lt;A href="https://help.qlik.com/talend/en-US/patch-notes/8.0/tps-6017" target="_blank" rel="noopener"&gt;TPS-6017&lt;/A&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;January 16, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="width: 29.9921%;"&gt;Talend Jobserver 7.3&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="width: 19.9815%;"&gt;TPS-6018&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="width: 19.9815%;"&gt;January 16, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="29.9921%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 29.9921%;"&gt;Talend Runtime 8.0&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;&lt;A href="https://help.qlik.com/talend/en-US/patch-notes/8.0/r2026-01-rt" target="_blank" rel="noopener"&gt;8.0.1.R2026-01-RT&lt;/A&gt;&lt;/TD&gt;
&lt;TD width="19.9815%" height="46px" class="lia-align-left" style="background-color: ghostwhite; width: 19.9815%;"&gt;January 24, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD height="24px" style="width: 29.9921%;"&gt;Talend Runtime 7.3&lt;/TD&gt;
&lt;TD height="24px" style="width: 19.9815%;"&gt;7.3.1-R2026-01&lt;/TD&gt;
&lt;TD height="24px" style="width: 19.9815%;"&gt;January 24, 2026&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Wed, 15 Apr 2026 08:52:30 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/ta-p/2541970</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2026-04-15T08:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Critical Security fix for the Qlik Talend JobServer and Talend Runtime (CVE-2026-pending)</title>
      <link>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/tac-p/2541974#M16810</link>
      <description>&lt;P&gt;&lt;SPAN&gt;For discussions and questions, comment directly on the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.qlik.com/t5/Support-Updates/Qlik-Talend-Job-Server-and-Talend-Runtime-New-Security-Patches/ba-p/2541972" target="_blank" rel="noopener" aria-describedby="audioeye_new_window_message"&gt;related blog post&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; We will be monitoring it. Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 15:19:13 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/tac-p/2541974#M16810</guid>
      <dc:creator>Sonja_Bauernfeind</dc:creator>
      <dc:date>2026-01-29T15:19:13Z</dc:date>
    </item>
  </channel>
</rss>

