CVE-2026-35194Disclosure(apache / flink)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache flink systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals and inject arbitrary expressions. Users are recommended to upgrade to either version 1.20.4, 2.0.2, 2.1.2 or 2.2.1, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flink

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Disclosures: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-18); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
flink

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-05-17: 1Mentions · 2026-05-18: 2Mentions · 2026-05-20: 2Mentions · 2026-05-26: 1Mentions · 2026-05-30: 1Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-18: 2Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-20: 2Technical Details · 2026-05-26: 105-1705-1805-2005-2605-3005-31
Signal classification4 categories
Disclosure
562.5%
Disclosures
112.5%
Patch
112.5%
General
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-171
Disclosures1
2026-05-182
Disclosure1Patch1
2026-05-202
Disclosure2
2026-05-261
Disclosure1
2026-05-301
Disclosure1
2026-05-311
General1
Full discourse8 posts
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad crítica en Apache Flink permite ejecución remota de código (CVE-2026-35194) que permite la ejecución remota de código (RCE). Falta de sanitización de las entradas del usuario permite ataques de inyección SQL en entornos de procesamiento de datos distribuidos https://blog.elhacker.net/2026/05/vulnerabilidad-critica-en-apache-flink.html

    Post summary

    Apache Flink’s CVE‑2026‑35194 is a critical vulnerability that allows remote code execution via unsanitized user input, also enabling SQL injection, though no exploitation or patch details are provided.

    0501321.3K
    141.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical CVE-2026-35194 flaw in Apache Flink allows RCE via SQL injection on TaskManagers. Upgrade your clusters immediately to secure your data! #ApacheFlink #CyberSecurity #InfoSec #RCE #DataEngineering #VulnerabilityAlert #CVE202635194 #BigData https://securityonline.info/apache-flink-vulnerability-cve-2026-35194-rce-sql-injection/ https://t.co/Qm3VBP5bsR

    Post summary

    A critical RCE vulnerability (CVE‑2026‑35194) in Apache Flink allows SQL injection on TaskManagers; users are urged to upgrade their clusters to mitigate the risk.

    02092938
    12.5K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Apache Flinkで深刻なRCE脆弱性CVE-2026-35194が公開された。SQL処理の欠陥を悪用すると、権限を持つ利用者が細工したクエリ経由で任意コードを実行できる。リアルタイム分析基盤やデータパイプラインが乗っ取られる危険がある。 問題はApache FlinkのSQLコード生成処理に存在する。JSON関数やESCAPE句付きLIKE式の入力値が適切にエスケープされず、そのまま生成Javaコードへ埋め込まれるため、攻撃者は文字列リテラルを突破して任意のJava式を注入できる。これによりTaskManager上でリモートコード実行が可能になる。 影響を受けるのは1.15.0〜1.20.x系と2.0.0〜2.x系で、特に1.20.4未満、2.0.2未満、2.1.2未満、2.2.1未満が危険とされる。JSON関数は1.15.0以降、LIKE ESCAPE処理は1.17.0以降で影響を受ける。攻撃にはクエリ送信権限が必要だが、分析基盤や共有クラスタでは内部不正や認証済みアカウント侵害による悪用が懸念される。 開発側はコード生成時のサニタイズを強化した修正版を公開済みで、1.20.4、2.0.2、2.1.2、2.2.1への更新を強く推奨している。 https://securityonline.info/apache-flink-vulnerability-cve-2026-35194-rce-sql-injection/

    Post summary

    Apache Flink’s CVE‑2026‑35194 exposes a severe RCE through SQL injection; affected versions are listed and the vendor has released a patch with update guidance.

    000721.9K
    14.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-35194: Apache Flink: Remote code execution via SQL injection in code generation https://www.openwall.com/lists/oss-security/2026/05/15/20 Severity: critical User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals

    Post summary

    The advisory discloses CVE-2026-35194 as a critical remote code execution flaw in Apache Flink caused by unsanitized user input in code generation, but does not provide a PoC, exploit, or patch information.

    00060351
    4.7K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-35194 Apache Flink 1.15.0 から 1.20.x および 2.0.0 から 2.xの脆弱性について https://www.cybernote.click/2026/05/29/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-35194-apache-flink-1-15-0-%e3%81%8b%e3%82%89-1-20-x-%e3%81%8a%e3%82%88%e3%81%b3-2-0-0-%e3%81%8b%e3%82%89-2-x%e3%81%ae%e8%84%86/ #IT #Security #cybersecurity

    Post summary

    The post merely announces that CVE‑2026‑35194 affects specific Apache Flink versions and provides a link to an external page, offering no technical details, exploit information, or mitigation guidance.

    0001052
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【脆弱性情報】 CVE-2026-35194 Apache Flink 1.15.0 から 1.20.x および 2.0.0 から 2.xの脆弱性について https://www.cybernote.click/2026/05/29/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-35194-apache-flink-1-15-0-%e3%81%8b%e3%82%89-1-20-x-%e3%81%8a%e3%82%88%e3%81%b3-2-0-0-%e3%81%8b%e3%82%89-2-x%e3%81%ae%e8%84%86/ #IT #Security #cybersecurity

    Post summary

    The post announces the existence of CVE-2026-35194 affecting certain Apache Flink releases, linking to a source for details, but provides no specific technical, exploit, or mitigation information.

    0000046
    209 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache Flink の脆弱性 CVE-2026-35194 が FIX:SQL コード生成の欠陥と任意のコード実行 https://iototsecnews.jp/2026/05/19/critical-apache-flink-vulnerability-enables-remote-code-execution-attacks/ Apache Flink の脆弱性 CVE-2026-35194 (RCE) の原因は、裏側で動くプログラムの仕組みにあります。 Flink では SQL から Java へのコード変換が行われますが、その際にユーザーが入力した文字列が適切な検証やエスケープなしに直接挿入されてしまう、安全でない文字列補間が生じます。その結果として、悪意のクエリにより Java コードの文字列リテラルからのエスケープが生じ、任意のコード実行へと至ってしまいます。ご利用のチームは、ご注意ください。 #Apache #CVE202635194 #Flink #Vulnerability

    Post summary

    The article discloses a remote code execution flaw in Apache Flink caused by unsafe string interpolation during SQL-to-Java code generation, but it does not provide a PoC, patch, or evidence of active exploitation.

    0000076
    490 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosures

    Apache Flink RCE Flaw (CVE-2026-35194) Exposes Clusters to Cyberattacks https://thecybrdef.com/apache-flink-cve-2026-35194-rce-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    Apache Flink RCE vulnerability (CVE-2026-35194) has been disclosed, potentially enabling remote code execution on clusters, with no exploit or patch information provided.

    0000058
    9 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheflink---
Appapacheflink2.2.0--
Appapacheflink2.2.0--
Appapacheflink2.2.0--

Explore more