๐Ÿ” CVE Alert

CVE-2026-40563

HIGH 7.1

Apache Atlas: Script injection allows access to unintended data

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data Affect Version: This issue affects Apache Atlas: from 0.8 through 2.4.0. For the affect version >= 2.0, vulnerability is only when Atlas is deployed with below non-default configuration. atlas.dsl.executor.traversal=false Mitigation: Users are recommended to upgrade to version 2.5.0, which fixes the issue.

CWE CWE-94
Vendor apache software foundation
Product apache atlas
Published May 4, 2026
Last Updated May 4, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache atlas

Be the first to know when new high vulnerabilities affecting apache software foundation apache atlas are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Atlas
0.8 โ‰ค 2.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/vd0oggmqxl2k1skm0z2f9p0plx7jhmfl openwall.com: http://www.openwall.com/lists/oss-security/2026/05/03/9

Credits

Khaled M. Alshammri qx L