PT-2026-24800 · Maven+2 · Io.Unitycatalog:Unitycatalog-Server+1

Lukas-Reining

·

Publicado

2026-03-11

·

Atualizado

2026-05-13

·

CVE-2026-27478

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Unity Catalog versions 0.4.0 and earlier
Description Unity Catalog is an open, multi-modal Catalog for data and AI. A critical authentication bypass exists in the Unity Catalog token exchange endpoint, /api/1.0/unity-control/auth/tokens. The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider. This allows an attacker to forge any user identity by pointing validation to their own JWKS endpoint.
Recommendations Versions prior to 0.4.0 should be used.

Exploit

Correção

Origin Validation Error

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27478
GHSA-QQCJ-RGHW-829X

Produtos afetados

Io.Unitycatalog:Unitycatalog-Server
Unitycatalog