---
id: CVE-2025-14262
title: >-
  A wrong permission check in KNIME Business Hub before version 1.17.0 allowed
  an authenticated user to save jobs of other users as if there were saved by
  the job owner
summary: >-
  A wrong permission check in KNIME Business Hub before version 1.17.0 allowed
  an authenticated user to save jobs of other users as if there were saved by
  the job owner. The attacker must have permissions to access the jobs but then
  they w…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-708
vendor: knime
product: business_hub
affected:
  - business_hub < 1.17.0
patched:
  - business_hub 1.17.0
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14262'
references:
  - url: 'https://www.knime.com/security/advisories#CVE-2025-11239'
    label: security@knime.com
tags:
  - nvd
epss: 0.00181
epssPercentile: 0.06972
ingestedAt: '2026-10-07T20:46:46.761Z'
---

## Overview

A wrong permission check in KNIME Business Hub before version 1.17.0 allowed an authenticated user to save jobs of other users as if there were saved by the job owner. The attacker must have permissions to access the jobs but then they were saved into the catalog service using the wrong owner permissions. Therefore it may have been possible to save into spaces where the attacker does not have write permissions.

There is no workaround.

## Affected

- `business_hub < 1.17.0`

## Remediation

Upgrade past the affected range:

- `business_hub 1.17.0`
