PT-2025-39922 · Knowage+1 · Knowage+1

Trganda

·

Published

2025-09-29

·

Updated

2025-09-30

·

CVE-2025-59954

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Knowage versions 8.1.26 and below
Description Knowage is an analytics and business intelligence suite. Versions 8.1.26 and below are susceptible to Remote Code Execution due to the use of an unsafe org.apache.commons.jxpath.JXPathContext in the MetaService.java service. The issue is addressed in version 8.1.27. The vulnerable component allows for unauthenticated Remote Code Execution with full system impact.
Recommendations Update to Knowage version 8.1.27 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00115
CVE-2025-59954
GHSA-96CV-75HG-XRGQ

Affected Products

Apache Commons Jxpath
Knowage