PT-2026-36788 · Apache · Apache Atlas

·

CVE-2026-40563

·

Published

2026-05-04

·

Updated

2026-07-21

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Atlas versions 0.8 through 2.4.0
Description An improper control of code generation issue exists in the DSL search endpoint, which accepts user-supplied query strings. An attacker can alter Gremlin traversal logic using grammar-allowed characters to access unintended data. For versions 2.0 and later, this issue only occurs when the software is deployed with the non-default configuration atlas.dsl.executor.traversal=false.
Recommendations Upgrade to version 2.5.0.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SH44648
CVE-2026-40563
GHSA-35XX-9XRG-GWHF

Affected Products

Apache Atlas