CVE-2026-40563General(apache / atlas)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache atlas systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data Affect Version: This issue affects Apache Atlas: from 0.8 through 2.4.0. For the affect version >= 2.0, vulnerability is only when Atlas is deployed with below non-default configuration. atlas.dsl.executor.traversal=false Mitigation: Users are recommended to upgrade to version 2.5.0, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • atlas

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-03); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
atlas

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-03: 1Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 105-0305-0405-05
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-031
General1
2026-05-041
Disclosure1
2026-05-051
Patch1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical injection flaw (CVE-2026-40563) in Apache Atlas lets attackers manipulate Gremlin logic to extract restricted enterprise data. Patch to v2.5.0 #ApacheAtlas #CyberSecurity #InfoSec #CVE202640563 #DataGovernance #Hadoop #CodeInjection #PatchAlert https://securityonline.info/apache-atlas-cve-2026-40563-gremlin-code-injection-data-breach/ https://t.co/8P9c1K7R4b

    Post summary

    The post announces a critical injection flaw in Apache Atlas (CVE‑2026‑40563), highlights the ability to manipulate Gremlin logic to steal data, and provides a patch version (v2.5.0).

    0601741.0K
    12.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-40563: Apache Atlas: Script injection allows access to unintended data https://www.openwall.com/lists/oss-security/2026/05/03/9 Severity: important Exposed DSL search endpoint accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters.

    Post summary

    The post discloses a script injection flaw in Apache Atlas that lets attackers modify Gremlin traversal via the DSL search endpoint but provides no PoC, exploit, or evidence of active use.

    02071584
    4.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40563 CVE-2026-40563 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40563

    Post summary

    The note simply repeats the CVE identifier and links to a Vulmon details page, offering no additional context on exploitation, patching, or technical specifics.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheatlas---

Explore more