CVE-2026-40563 (CVSS 7.1) - Description: Improper Control of Generation of Code ('Code Injection') vulnerabi

📡 NVD-Latest · 2026-05-04

CVE-2026-40563 (CVSS 7.1) - Description: Improper Control of Generation of Code ('Code Injection') vulnerabi

CVE-2026-40563

CVE-2026-40563 CVSS:7.1

Description:

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas

Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data

Affect Version:

This issue affects Apache Atlas: from 0.8 through 2.4.0.

For the affect version >= 2.0, vulnerability is only when Atlas is deployed with below non-default configuration.

atlas.dsl.executor.traversal=false

Mitigation:

Users are recommended to upgrade to version 2.5.0, which fixes the issue.

产品: apache atlas


📌 来源: NVD-Latest | 🆔 CVE-2026-40563 | 📅 2026-05-04

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)