CVE-2026-57111Disclosure(apache / helix)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1385

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • helix

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
helix

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-57111: Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin https://www.openwall.com/lists/oss-security/2026/07/08/11 Severity: low Helix is a generic cluster management framework. It automates reassignment of resources in the face of node failure and recovery.

    Post summary

    The notice announces CVE-2026-57111, labeling it a low‑severity permissive CORS flaw in Apache Helix’s REST API, with no known exploits, patches, or proof of concept shared.

    00010518
    4.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehelix---

Explore more