Security

Warning

Important note about copy.fail (CVE-2026-31431), dirtyfrag.io (CVE-2026-43284 / CVE-2026-43500), Fragnesia (CVE-2026-46300), ssh-keysign-pwn (CVE-2026-46333)

Like all Linux-based machines, virtual machines and containers running Dataiku are affected by these recent Linux Local Privilege Escalation vulnerabilities. They notably affect the isolation provided by UIF, allowing regular users to break out of the isolated Unix user.

For Dataiku Cloud, fixes have already been applied on our whole infrastructure. No further action is required.

For Dataiku Cloud Stacks installs, please use the following procedure:

Run, as root:

dnf update --security
reboot

Note that if you reprovision, you must run it again.

For Dataiku Custom installs, the OS is not managed by Dataiku. Please refer to instructions from your OS provider.

For containerized execution and Dataiku itself running in containers, please refer to instructions from your Kubernetes cluster provider.