CVE-2026-3053

A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file dinky-admin/src/main/java/org/dinky/configure/AppConfig.java of the component OpenAPI Endpoint. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/AnalogyC0de/public_exp/issues/6 Issue Tracking Exploit Third Party Advisory
https://github.com/AnalogyC0de/public_exp/issues/6#issue-3935019636 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.347411 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.347411 Third Party Advisory VDB Entry
https://vuldb.com/?submit.757589 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:dinky:dinky:*:*:*:*:*:*:*:*

History

25 Feb 2026, 19:43

Type Values Removed Values Added
References () https://github.com/AnalogyC0de/public_exp/issues/6 - () https://github.com/AnalogyC0de/public_exp/issues/6 - Issue Tracking, Exploit, Third Party Advisory
References () https://github.com/AnalogyC0de/public_exp/issues/6#issue-3935019636 - () https://github.com/AnalogyC0de/public_exp/issues/6#issue-3935019636 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.347411 - () https://vuldb.com/?ctiid.347411 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.347411 - () https://vuldb.com/?id.347411 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.757589 - () https://vuldb.com/?submit.757589 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:dinky:dinky:*:*:*:*:*:*:*:*
Summary
  • (es) Se encontró una vulnerabilidad en DataLinkDC dinky hasta 1.2.5. Esta afecta la función addInterceptors del archivo dinky-admin/src/main/java/org/dinky/configure/AppConfig.java del componente OpenAPI Endpoint. Si se manipula y ejecuta se puede provocar una falta de autenticación. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado públicamente y puede ser utilizado. El proveedor fue contactado con anterioridad sobre esta divulgación pero no respondió de ninguna manera.
First Time Dinky
Dinky dinky

24 Feb 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 02:16

Updated : 2026-02-25 19:43


NVD link : CVE-2026-3053

Mitre link : CVE-2026-3053

CVE.ORG link : CVE-2026-3053


JSON object : View

Products Affected

dinky

  • dinky
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function