CVE-2026-27478Disclosure(unitycatalog / unitycatalog)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch unitycatalog unitycatalog systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290CWE-346CWE-1390

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unitycatalog

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-11); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
unitycatalog

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-11: 3Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-03-11: 3Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 103-1105-1105-13
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure3
2026-05-111
Patch1
2026-05-131
Disclosure1
Full discourse5 posts
  • Technology Interpreters, Inc.@TechTranslators
    Disclosure

    Two auth-bypass bugs disclosed in the last 48 hours. Look totally different. Same bug. SillyTavern (CVE-2026-44649) and Databricks' Unity Catalog (CVE-2026-27478) both shipped a server that believed what the client said about who it was.

    Post summary

    Both CVEs are newly disclosed auth-bypass bugs; the tweet announces their discovery without detailing exploitation, patches, or PoC references.

    10000101
    35 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Unity Catalog JWT Issuer Validation Bypass (CVE-2026-27478) A critical authentication bypass exists in the Unity Catalog server's token exchange endpoint. The system extracts the issuer (iss) claim from incoming JWTs and fetches the JWKS endpoint for signature validation without verifying if the issuer is trusted. This allows an attacker to host a malicious OIDC server and impersonate any user, gaining full access to all catalogs and resources. 👉 Affected: Unity Catalog <= 0.4.0 | Upgrade to 0.4.1

    Post summary

    A critical authentication bypass in Unity Catalog’s token exchange endpoint is disclosed; upgrading to version 0.4.1 resolves the issue.

    00010113
    187 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27478: Unity Catalog has a JWT Issuer V... Attacker-controlled JWT issuer claims let you forge any user identity by pointing validation to your own JWKS endpoint ... https://zerodaysignal.com/vulnerability/CVE-2026-27478 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed vulnerability in Unity Catalog enables attackers to forge JWT issuers and impersonate any user by pointing validation to a custom JWKS endpoint.

    0001084
    143 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27478 Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token … https://www.cve.org/CVERecord?id=CVE-2026-27478

    Post summary

    The entry announces a critical authentication bypass in Unity Catalog versions 0.4.0 and earlier, providing basic technical details but no PoC, exploit code, or patch information.

    00000193
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27478: CRITICAL] Critical authentication bypass vulnerability identified in Unity Catalog versions 0.4.0 and earlier. This flaw in the token exchange endpoint could allow unauthorized access. #Cybe...#cve,CVE-2026-27478,#cybersecurity https://cvefind.com/CVE-2026-27478

    Post summary

    The tweet reports a critical authentication bypass vulnerability (CVE-2026-27478) for Unity Catalog 0.4.0 and earlier, indicating that the token exchange endpoint can be exploited for unauthorized access; no PoC, exploit, or patch details are provided.

    0000092
    600 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appunitycatalogunitycatalog---

Explore more