PT-2026-6808 · Datahub · Datahub

Arad Inbar

+2

·

Published

2026-02-06

·

Updated

2026-02-06

·

CVE-2026-25644

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DataHub versions prior to 1.3.1.8
Description DataHub, an open-source metadata platform, has an issue in its LDAP ingestion source. Specifically, versions before 1.3.1.8 are susceptible to a man-in-the-middle (MITM) attack due to a TLS downgrade. This allows an attacker to intercept and potentially modify communications between the DataHub platform and the LDAP server.
Recommendations Update to DataHub version 1.3.1.8 or later.

Exploit

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-25644
GHSA-J34H-X7QG-4QW5

Affected Products

Datahub