SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-50622

HIGH · CVSS 8.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Apache Atlas contains a missing authorization vulnerability in its admin endpoints, enabling any authenticated user to execute administrative operations without proper role validation. This flaw poses a significant risk, as it can lead to unauthorized access and manipulation of sensitive data. Organizations using affected versions (0.8 to 2.5.0) should prioritize upgrading to version 2.6.0 to mitigate this high-severity issue.

CVE
CVE-2026-50622
Severity
HIGH
CVSS
8.8
EPSS
0.34%
Apache

Original NVD Description

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)