Tarkov operates a data-management product where the observed vulnerability pattern centers on web application and authentication handling, with recurring weaknesses including type confusion, improper authentication, cross-site scripting, SQL injection, and prototype pollution. These weaknesses are typical of server-side applications that process untrusted input and manage client state; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tarkov over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21854CRITICAL The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, an authentication bypass vulnerability in the login endpoint allows any unauthenticated | Jan 7, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-21856HIGH The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vulnerability in the we | Jan 7, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-21855MEDIUM The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to 02 January 2025, a reflected Cross Site Scripting (XSS) vulnerability in the toast notification system al | Jan 7, 2026 | 6.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tarkov.
Media articles that mention a CVE ID that affects a product developed by Tarkov — matched by CVE ID, not by vendor name.