๐Ÿ” CVE Alert

CVE-2024-49587

CRITICAL 9.1

Glutton V1 endpoints missing authentication

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has been patched and automatically deployed to all Apollo-managed Gotham Instances

CWE CWE-305
Vendor palantir
Product com.palantir.gotham:glutton
Published Dec 19, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for palantir com.palantir.gotham:glutton

Be the first to know when new critical vulnerabilities affecting palantir com.palantir.gotham:glutton are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Palantir / com.palantir.gotham:glutton
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
palantir.safebase.us: https://palantir.safebase.us/?tcuUid=95e2d805-dd2f-4544-b164-e61100f47b11