CVE-2025-59954

CRITICAL

Knowage < 8.1.27 - Remote Code Execution via Unsafe JXPathContext in MetaService

Title source: llm
STIX 2.1

Description

Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue is fixed in version 8.1.27.

Scores

CVSS v3 9.8
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
eng/knowage < 8.1.27
Published Sep 30, 2025
Tracked Since Feb 18, 2026