OVERVIEW CVE-2026-35052 affects D-Tale versions prior to 3.22.0, a Flask and React-based data analysis platform. The vulnerability allows remote code execution when D-Tale is publicly hosted with redis or shelf storage backends enabled, potentially granting attackers the ability to execute arbitrary code on affected servers. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.8 (CRITICAL) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The impact is severe, with confirmed high-severity consequences for confidentiality, integrity, and availability. The FAUCET risk score of 55.0/100 reflects substantial risk, though the low EPSS score of 0.001 indicates current exploit activity remains minimal relative to other disclosed vulnerabilities. EXPLOITATION STATUS While not currently listed in the Known Exploited Vulnerabilities (KEV) catalog, the vulnerability has been flagged on the active Hot List, suggesting emerging community attention and potential exploitation activity. Organizations running publicly accessible D-Tale instances with redis or shelf storage should prioritize immediate patching to version 3.22.0 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.22.0CPE matchmatch criteria | cpe:2.3:a:man:d-tale:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.