Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Talend Cloud AWS EU Scheduled Outage: Starting Tues 26 May 21:00 CEST with expected completion Wed 27 May 01:00 CEST
Sonja_Bauernfeind
Digital Support
Digital Support

Edited 15th April, 2026: Added recently assigned CVE number (CVE-2026-6264)

Hello Qlik Users,

A critical security issue in the Talend JobServer and Talend Runtime has been identified. This issue was resolved in later patches, which are already available. Details can be found in the Security Bulletin Critical Security fix for the Qlik Talend JobServer and ESB Runtime (CVE-2026-6264).

 

Affected Software

  • All versions of Talend JobServer before TPS-6017 (8.0) or TPS-6018 (7.3).
  • All versions of Talend Runtime before 8.0.1.R2026-01-RT or 7.3.1-R2026-01

 

Recommendation

Upgrade at the earliest. The following table lists the patch versions addressing the vulnerability (CVE-2026-6264).

Always update to the latest version. Before you upgrade, check if a more recent release is available.
 Product Patch Release Date
Talend JobServer 8.0 TPS-6017 January 16, 2026
Talend Jobserver 7.3 TPS-6018 January 16, 2026
Talend Runtime 8.0 8.0.1.R2026-01-RT January 24, 2026
Talend Runtime 7.3 7.3.1-R2026-01 January 24, 2026
The Remote Engine and Dynamic Engine are not impacted by this vulnerability. However, we will update the embedded jobserver in version 2.14.1 of the remote engine available in February 2026.

 

Thank you for choosing Qlik,
Qlik Support

17 Comments
yfujioka
Partner - Creator
Partner - Creator

CVE-2026-pendingで見つかった重大なセキュリティの問題はJobserverとRuntimeが外部のインターネットと通信できない状態でも影響がありますか?

0 Likes
359 Views
DaniZ
Partner - Contributor II
Partner - Contributor II

Hi,

Since applying the R2026-01 Runtime patch, the monitoring port doesn't seem to be operational at all.

When I set it to true, the entire server goes DOWN.

If I set it to false, the server goes to UP: but the MonitoringPort is misconfigured.

Was this what the patch was supposed to do? Is there an alternative way to use the monitoring port, or was this simply an emergency measure to disable its functionality until a proper fix can be applied to the JMX code?

323 Views
Björn_N
Contributor II
Contributor II

We're having the same issues with server down after applying the patch.

On 2026-01 and 2026-02v2 the server will appear down in TAC if the monitoring port is enabled. Will cycle up/down if disabled.

0 Likes
274 Views
DaniZ
Partner - Contributor II
Partner - Contributor II

Actually - it seems to have been fixed in 2026-02. There is a clear distinction between a Job Server config and a Runtime Server config, so monitoring and process message ports no longer appear under the Runtime Server ports config and np DOWN status is generated by them.

However, please note that you need an updated version of TAC to see this change. So it would be best to upgrade to the latest QTAC-1884 (it also worked in QTAC-1883).

0 Likes
248 Views
Björn_N
Contributor II
Contributor II

Ok, thx. Had issues with both on a live runtime.

Upgraded a minimal conf:ed runtime to 2026_01 to exclude anything we had adjusted. Will try bumping it up to _02v2 then.

 

0 Likes
232 Views
Björn_N
Contributor II
Contributor II

On QTAC-1884 as well.

Bumped it up to 2026-02v2, look like my problem now is that my monitoring port is only listening on 127.0.0.1 so the tac will not be able to access it on a separate server.
The patch restricted 3 others to localhost, fixed those but can't seem to find a way to change that.

0 Likes
208 Views
DaniZ
Partner - Contributor II
Partner - Contributor II

You can change IP assignment in /runtime/etc/org.apache.karaf.management.cfg

But you can now turn off the Job Server section and then the Runtime Server section isn't affected by the monitoring port anymore

0 Likes
199 Views