Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6264

34
FAUCET Score

CVE-2026-6264 is a critical remote code execution vulnerability affecting Talend JobServer and Talend Runtime that exploits the JMX monitoring port to enable unauthenticated attacks. This vulnerability poses significant risk to organizations running affected Talend products as an entry point for unauthorized system compromise. The vulnerability presents a network-based attack vector with low complexity and no authentication requirements, resulting in a critical CVSS score of 9.8. Successful exploitation grants attackers complete system access with high impact across confidentiality, integrity, and availability. TLS client authentication can provide temporary mitigation for JobServer; however, official patches are required for comprehensive protection. No active exploitation has been documented at this time, as the vulnerability is not included on the CISA KEV catalog and remains inactive on the Hot List. The EPSS score of 0.00097 indicates relatively low predicted likelihood of real-world exploitation compared to the broader CVE population, suggesting this remains primarily a theoretical threat despite its critical severity rating.

Impacted Technologies

VendorProductVersion(s)CPE
TalendTalend JobServer
>= 8.0, < TPS-6017, >= 7.3, < TPS-6018CNA affecteddefault unaffected
TalendTalend Runtime
>= 7.3, < 7.3.1-R2026-01, >= 8.0, < 8.0.1.R2026-01-RTCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
50.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0074 is in the 34th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

community.qlik.com / t5/Official-Support-Articles/Critical-Security-fix-for-the-Qlik-Talend-JobServer-and-Talend/tac-p/2541974