PT-2026-24800 · Maven+2 · Io.Unitycatalog:Unitycatalog-Server+1
Lukas-Reining
·
Published
2026-03-11
·
Updated
2026-05-13
·
CVE-2026-27478
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Unity Catalog versions 0.4.0 and earlier
Description
Unity Catalog is an open, multi-modal Catalog for data and AI. A critical authentication bypass exists in the Unity Catalog token exchange endpoint,
/api/1.0/unity-control/auth/tokens. The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider. This allows an attacker to forge any user identity by pointing validation to their own JWKS endpoint.Recommendations
Versions prior to 0.4.0 should be used.
Exploit
Fix
Authentication Bypass by Spoofing
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Io.Unitycatalog:Unitycatalog-Server
Unitycatalog