Description
It is possible to make a specially crafted request with a valid API token that leads to privilege escalation.
Recommendation
Update the @cubejs-backend/server-core package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.5.0, < 1.5.13 >= 1.1.0, < 1.4.2 >= 0.27.19, < 1.0.14** Patched version(s): **1.5.13 1.4.2 1.0.14**
References
Could your website be exposed too?
SmartScanner can check your website for Cube Core is vulnerable to privilege escalation via a specially crafted request and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag - CVE-2026-8813
- OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation - CVE-2024-29194
- Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline - CVE-2026-27739
You might also like:
See something that needs correcting? Let us knowUpdated February 10, 2026


