CVE-2026-3053

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/AnalogyC0de/public_exp/issues/6 Issue Tracking Exploit Third Party Advisory
https://github.com/AnalogyC0de/public_exp/issues/6#issue-3935019636 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.347411 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.347411 Third Party Advisory VDB Entry
https://vuldb.com/?submit.757589 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:dinky:dinky:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-24 02:16

Updated : 2026-02-25 19:43


NVD link : CVE-2026-3053

Mitre link : CVE-2026-3053

CVE.ORG link : CVE-2026-3053


JSON object : View

Products Affected

dinky

  • dinky
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function