216.73.216.6

CVE-2026-41132

· Published 13/05/2026 19:17 · Modified 14/05/2026 16:26

Labels: CVE-2026-41132 2026-05-13CVE-2026-41132CWE-295[email protected]

Essential information

Published
13/05/2026 19:17
Modified
14/05/2026 16:26
Author
Creator
CVSS
6.6 MEDIUM (v3) 6.6 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks. This vulnerability is fixed in 2.10.10 and 2.11.5.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ckan / ckan cpe:2.3:a:ckan:ckan:<2.10.10:*:*:*:*:*:*:*
ckan / ckan cpe:2.3:a:ckan:ckan:<2.11.5:*:*:*:*:*:*:*

References