216.73.216.6

CVE-2025-59954

· Published 30/09/2025 11:37 · Modified 30/09/2025 15:15

Labels: CVE-2025-59954 2025-09-30CVE-2025-59954CWE-94[email protected]

Essential information

Published
30/09/2025 11:37
Modified
30/09/2025 15:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue is fixed in version 8.1.27.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
knowage / knowage cpe:2.3:a:knowage:knowage:8.1.26:*:*:*:*:*:*:*
knowage / knowage cpe:2.3:a:knowage:knowage:<8.1.27:*:*:*:*:*:*:*

References