CVE-2026-41042Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. This issue only happens when using H2, and H2 is mainly used for testing and local development. Also, Gravitino is typically deployed in the internal environment, so the severity is low.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-07-09); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-09: 1Mentions · 2026-08-19: 1Mentions · 2026-08-29: 1PoC Mentioned / Linked · 2026-08-19: 1PoC Mentioned / Linked · 2026-08-29: 1Exploit Tool / Code · 2026-08-29: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-29: 107-0908-1908-29
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-091
Disclosure1
2026-08-191
Disclosure1
2026-08-291
PoC1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41042 - critical 🚨 Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution > Apache Gravitino < 1.2.1 contains a remote code execution caused by unsanitized H2 JD... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41042 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑41042, an unauthenticated RCE in Apache Gravitino versions below 1.2.1 caused by unsanitized H2 JD, and provides a link to a ProjectDiscovery library entry for further details.

    01003281.7K
    1.3K followersView on X
  • Killed More 🐈‍⬛ Than Curiosity@Lulztigre
    PoC

    Dropped the first PoC for CVE-2026-41042 – unauth RCE in Apache Gravitino. testConnection sends user JDBC URL to H2, where INIT runs arbitrary SQL and CREATE ALIAS gives Java. No auth. Credit: Junjie Li. Writeup & PoC by me. https://lulztigre.pw/posts/gravitino-test-connection-rce-41042.html https://github.com/lulztigre/cve-2026-41042

    Post summary

    The author released the first PoC for CVE-2026-41042, an unauthenticated RCE in Apache Gravitio via testConnection JDBC injection, and linked to a writeup and GitHub exploit repo. No patch, active exploitation, or false positive claims are present.

    251242959
    1.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41042: Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter https://www.openwall.com/lists/oss-security/2026/07/08/5 Severity: low

    Post summary

    The text announces CVE-2026-41042 in Apache Gravitino, detailing how unauthenticated callers can cause arbitrary Java code execution via a crafted H2 JDBC URL, without mentioning exploits or patches.

    00020620
    4.7K followersView on X

Explore more