{"id":"CVE-2026-42160","summary":"Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend","details":"Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered \"PENDING\" organization / user accounts. This issue has been patched in version 7.3.2.","aliases":["GHSA-989g-wpfv-6vxx"],"modified":"2026-08-12T16:24:17.623612Z","published":"2026-05-08T19:46:59.825Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-602","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42160.json"},"references":[{"type":"WEB","url":"https://github.com/sovity/dataspace-portal/releases/tag/v7.3.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42160.json"},{"type":"ADVISORY","url":"https://github.com/sovity/dataspace-portal/security/advisories/GHSA-989g-wpfv-6vxx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42160"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sovity/dataspace-portal","events":[{"introduced":"cf1f505c2d3c2ae4f8b23c25efec382946aa1d76"},{"fixed":"55eb7e0aa069a51b740ecd2eb84876b187b15441"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"2.1.1"},{"fixed":"7.3.2"},{"introduced":"0"}]}}],"versions":["v7.3.0","v7.2.0","v7.1.0","v7.0.0","v6.0.0","v5.0.0","v4.1.1","v4.1.0","v2.3.0","v4.0.0","v3.1.0","v3.0.0","v2.2.1","v2.2.0","v2.1.2","v2.1.1"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["7845663546933880001902440684475373550","115472570737576850378004706492465231456","338149105797791391724664141706999174850","24013922377763457135712913010435517495","132630832062794524522807003445757561596","285492173793983188932157073079722519075","254838260443259631951673240964957152556","15066167790780630088196198790886883895","278555252725300429562248199415628765515","217738757461555548793459099169807858909"],"threshold":0.9},"id":"CVE-2026-42160-21965730","signature_type":"Line","signature_version":"v1","source":"https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441","target":{"file":"authority-portal-backend/catalog-crawler/catalog-crawler/src/test/java/de/sovity/edc/ext/catalog/crawler/crawling/writing/ConnectorSuccessWriterTest.java"}},{"deprecated":false,"digest":{"line_hashes":["2421452242669647133412912943142212036","184014690797442484659812372005305414739","178086848181228023704161560228814098402","302838774276838612898873272412821324618","40649412793385306675317921174936761908","169583355321697189037846868553802240031","265562710518536323594300506864848386360","26570634636739222186613204490803156861","302798909564610057281983038613617089628","317813935319781888992161167322698898411","161991023434230082062482943734570345271","104628705238096096402380740218099793227"],"threshold":0.9},"id":"CVE-2026-42160-5f35961a","signature_type":"Line","signature_version":"v1","source":"https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441","target":{"file":"authority-portal-backend/catalog-crawler/catalog-crawler/src/main/java/de/sovity/edc/ext/catalog/crawler/CrawlerExtensionContextBuilder.java"}},{"deprecated":false,"digest":{"line_hashes":["335126369165179944636967516259221774639","210389391051195435567363864882008545128","25322837585791130317422297565234766466","173619945365302862383944127932893750487","140155172524885203617640002147470882929","259254682145727663334235824176731478167","17619368584712627070350148169886466818","197236191439141588130629800847049471754"],"threshold":0.9},"id":"CVE-2026-42160-7deff98a","signature_type":"Line","signature_version":"v1","source":"https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441","target":{"file":"authority-portal-backend/catalog-crawler/catalog-crawler/src/main/java/de/sovity/edc/ext/catalog/crawler/CrawlerExtension.java"}},{"signature_version":"v1","source":"https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441","target":{"file":"authority-portal-backend/catalog-crawler/catalog-crawler/src/test/java/de/sovity/edc/ext/db/TestDatabase.java"},"deprecated":false,"digest":{"line_hashes":["131454548699222088225830877647883877722","337865348101685104184378118069575877015"],"threshold":0.9},"id":"CVE-2026-42160-c3933965","signature_type":"Line"},{"id":"CVE-2026-42160-deed5af9","signature_type":"Line","signature_version":"v1","source":"https://github.com/sovity/dataspace-portal/commit/55eb7e0aa069a51b740ecd2eb84876b187b15441","target":{"file":"authority-portal-backend/catalog-crawler/catalog-crawler/src/main/java/de/sovity/edc/utils/config/model/ConfigProp.java"},"deprecated":false,"digest":{"line_hashes":["338263497417102824922480519037331279802","220692601692155722226210807748275082780"],"threshold":0.9}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42160.json","vanir_signatures_modified":"2026-08-12T16:24:17Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"}]}