CVE-2026-42160

Source
https://cve.org/CVERecord?id=CVE-2026-42160
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42160.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-42160
Aliases
  • GHSA-989g-wpfv-6vxx
Published
2026-05-08T19:46:59.825Z
Modified
2026-07-22T00:13:07.209497Z
Severity
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L CVSS Calculator
Summary
Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
Details

Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered "PENDING" organization / user accounts. This issue has been patched in version 7.3.2.

Database specific
{
    "cwe_ids": [
        "CWE-602",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42160.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/sovity/dataspace-portal

Affected ranges

Type
GIT
Repo
https://github.com/sovity/dataspace-portal
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.1.1"
        },
        {
            "fixed": "7.3.2"
        },
        {
            "introduced": "0"
        }
    ]
}

Affected versions

v2.*
v2.1.1
v2.1.2
v2.2.0
v2.2.1
v2.3.0
v3.*
v3.0.0
v3.1.0
v4.*
v4.0.0
v4.1.0
v4.1.1
v5.*
v5.0.0
v6.*
v6.0.0
v7.*
v7.0.0
v7.1.0
v7.2.0
v7.3.0

Database specific

vanir_signatures_modified
"2026-07-22T00:13:07Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "target": {
            "file": "authority-portal-backend/catalog-crawler/catalog-crawler/src/test/java/de/sovity/edc/ext/catalog/crawler/crawling/writing/ConnectorSuccessWriterTest.java"
        },
        "deprecated": false,
        "source": "https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441",
        "id": "CVE-2026-42160-21965730",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "7845663546933880001902440684475373550",
                "115472570737576850378004706492465231456",
                "338149105797791391724664141706999174850",
                "24013922377763457135712913010435517495",
                "132630832062794524522807003445757561596",
                "285492173793983188932157073079722519075",
                "254838260443259631951673240964957152556",
                "15066167790780630088196198790886883895",
                "278555252725300429562248199415628765515",
                "217738757461555548793459099169807858909"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "authority-portal-backend/catalog-crawler/catalog-crawler/src/main/java/de/sovity/edc/ext/catalog/crawler/CrawlerExtensionContextBuilder.java"
        },
        "deprecated": false,
        "source": "https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441",
        "id": "CVE-2026-42160-5f35961a",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "2421452242669647133412912943142212036",
                "184014690797442484659812372005305414739",
                "178086848181228023704161560228814098402",
                "302838774276838612898873272412821324618",
                "40649412793385306675317921174936761908",
                "169583355321697189037846868553802240031",
                "265562710518536323594300506864848386360",
                "26570634636739222186613204490803156861",
                "302798909564610057281983038613617089628",
                "317813935319781888992161167322698898411",
                "161991023434230082062482943734570345271",
                "104628705238096096402380740218099793227"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "authority-portal-backend/catalog-crawler/catalog-crawler/src/main/java/de/sovity/edc/ext/catalog/crawler/CrawlerExtension.java"
        },
        "deprecated": false,
        "source": "https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441",
        "id": "CVE-2026-42160-7deff98a",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "335126369165179944636967516259221774639",
                "210389391051195435567363864882008545128",
                "25322837585791130317422297565234766466",
                "173619945365302862383944127932893750487",
                "140155172524885203617640002147470882929",
                "259254682145727663334235824176731478167",
                "17619368584712627070350148169886466818",
                "197236191439141588130629800847049471754"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "authority-portal-backend/catalog-crawler/catalog-crawler/src/test/java/de/sovity/edc/ext/db/TestDatabase.java"
        },
        "deprecated": false,
        "source": "https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441",
        "id": "CVE-2026-42160-c3933965",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "131454548699222088225830877647883877722",
                "337865348101685104184378118069575877015"
            ],
            "threshold": 0.9
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "authority-portal-backend/catalog-crawler/catalog-crawler/src/main/java/de/sovity/edc/utils/config/model/ConfigProp.java"
        },
        "deprecated": false,
        "source": "https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441",
        "id": "CVE-2026-42160-deed5af9",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "338263497417102824922480519037331279802",
                "220692601692155722226210807748275082780"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42160.json"