Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
ALERT: QlikView server communication interruptions following Microsoft Windows Domain Controller security updates

Critical Security fix for the Qlik Talend JobServer and Talend Runtime (CVE-2026-6264)

100% helpful (2/2)
cancel
Showing results for 
Search instead for 
Did you mean: 
Sonja_Bauernfeind
Digital Support
Digital Support

Critical Security fix for the Qlik Talend JobServer and Talend Runtime (CVE-2026-6264)

Last Update:

Apr 15, 2026 4:52:30 AM

Updated By:

Sonja_Bauernfeind

Created date:

Jan 29, 2026 10:17:59 AM

Executive Summary

A critical security issue in the Talend JobServer and Talend Runtime has been identified. This issue was resolved in later patches, which are already available. If the vulnerability is successfully exploited, an attacker could gain full remote code execution on the Talend JobServer and Talend Runtime servers.

This issue was discovered by Harpreet Singh (@TheCyb3rAlphaProfession), Security Researcher.

Affected Software

  • All versions of Talend JobServer before TPS-6017 (8.0) or TPS-6018 (7.3).
  • All versions of Talend Runtime before 8.0.1.R2026-01-RT or 7.3.1-R2026-01

Severity Rating

Using the CVSS V3.1 scoring system (https://nvd.nist.gov/vuln-metrics/cvss), this issue is rated CRITICAL.

Vulnerability Details

CVE-2026-6264

Severity: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8 Critical)

A critical vulnerability has been found in the Talend JobServer and Talend Runtime that allows unauthenticated remote code execution

The attack vector for this vulnerability is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend Jobserver by requiring TLS client authentication for the monitoring port. However, the patch will need to be applied to fully mitigate the vulnerability.
For Talend Runtime, the vulnerability can be mitigated by disabling the JobServer JMX monitoring port, which is disabled by default from the 8.0 R2024-07-RT patch.

 

Resolution

Recommendation

Upgrade at the earliest. The following table lists the patch versions addressing the vulnerability (CVE-2026-6264).

Always update to the latest version. Before you upgrade, check if a more recent release is available.
 Product Patch Release Date
Talend JobServer 8.0 TPS-6017 January 16, 2026
Talend Jobserver 7.3 TPS-6018 January 16, 2026
Talend Runtime 8.0 8.0.1.R2026-01-RT January 24, 2026
Talend Runtime 7.3 7.3.1-R2026-01 January 24, 2026
Labels (1)
Comments
Sonja_Bauernfeind
Digital Support
Digital Support

For discussions and questions, comment directly on the related blog post.  We will be monitoring it. Thank you!

Contributors
Version history
Last update:
‎2026-04-15 04:52 AM
Updated by: