SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-32773

MEDIUM · CVSS 6.1 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-08

CyberRota Analysis

AI-Generated

The Spark History Server prior to version 3.5.8 is vulnerable to a lack of XSS escaping, allowing a malicious Spark job to inject arbitrary unescaped frontend code, which could lead to minimal privilege escalation in a user's browser. This vulnerability requires users to have the ability to launch Spark jobs and to trick higher-privileged users into accessing the affected web page. Organizations using Spark should prioritize upgrading to version 3.5.8 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-32773
Severity
MEDIUM
CVSS
6.1
EPSS
0.26%

Original NVD Description

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

Related CVEs

Other vulnerabilities affecting the same vendor(s)