Upwind Security MDR[verified]@UpwindMDRPatch
A critical authentication bypass in Unity Catalog’s token exchange endpoint is disclosed; upgrading to version 0.4.1 resolves the issue.
Technology Interpreters, Inc.@TechTranslatorsDisclosure
Both CVEs are newly disclosed auth-bypass bugs; the tweet announces their discovery without detailing exploitation, patches, or PoC references.
0day Signal@0dayPublishingDisclosure
A newly disclosed vulnerability in Unity Catalog enables attackers to forge JWT issuers and impersonate any user by pointing validation to a custom JWKS endpoint.
CVE@CVEnewDisclosure
The entry announces a critical authentication bypass in Unity Catalog versions 0.4.0 and earlier, providing basic technical details but no PoC, exploit code, or patch information.
CVEFind.com@CveFindComDisclosure
The tweet reports a critical authentication bypass vulnerability (CVE-2026-27478) for Unity Catalog 0.4.0 and earlier, indicating that the token exchange endpoint can be exploited for unauthorized access; no PoC, exploit, or patch details are provided.