PT-2026-24800 · Maven+2 · Io.Unitycatalog:Unitycatalog-Server+1

Lukas-Reining

·

Published

2026-03-11

·

Updated

2026-05-13

·

CVE-2026-27478

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Unity Catalog versions 0.4.0 and earlier
Description Unity Catalog is an open, multi-modal Catalog for data and AI. A critical authentication bypass exists in the Unity Catalog token exchange endpoint, /api/1.0/unity-control/auth/tokens. The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider. This allows an attacker to forge any user identity by pointing validation to their own JWKS endpoint.
Recommendations Versions prior to 0.4.0 should be used.

Exploit

Fix

Authentication Bypass by Spoofing

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-27478
GHSA-QQCJ-RGHW-829X

Affected Products

Io.Unitycatalog:Unitycatalog-Server
Unitycatalog