Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026
Spotfire OAuth2 PKCE Bypass for public clients
CVE-2026-8590
Description
Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules).
This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X.
Affected products
3- Range: <=14.0.12, <=14.4.2, <=14.5.0, <=14.6.1, <=14.6.2, <=14.7.0, <=14.8.0
- Range: <=14.0.12, <=14.5.0, <=14.6.0, <=14.6.1, <=14.6.2, <=14.7.0, <=14.8.0
- Range: <=4.2.0, 5.0.X, 6.0.X
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.