CVE-2026-8590: Spotfire Enterprise

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire Enterprise with External Consumers: through 14.0.12, through 14.5.0, through 14.6.0, through 14.6.1, through 14.6.2, through 14.7.0, through 14.8.0; Spotfire on Kubernetes: through 4.2.0, 5.0.X, 6.0.X.

Affected products

  • Spotfire Spotfire Enterprise: up to and including 14.0.12; up to and including 14.4.2; up to and including 14.5.0; up to and including 14.6.1; up to and including 14.6.2; up to and including 14.7.0; …
  • Spotfire Spotfire Enterprise With External Consumers: up to and including 14.0.12; up to and including 14.5.0; up to and including 14.6.0; up to and including 14.6.1; up to and including 14.6.2; up to and including 14.7.0; …
  • Spotfire Spotfire On Kubernetes: up to and including 4.2.0; from 5.0, before 5.1 (fixed in 5.1); from 6.0, before 6.1 (fixed in 6.1)

Published 2026-07-14. Last modified 2026-07-15.