PT-2026-36788 · Apache · Apache Atlas

Qx L

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-40563

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Atlas versions 0.8 through 2.4.0
Description An improper control of code generation issue exists in the DSL search endpoint, which accepts user-supplied query strings. An attacker can alter Gremlin traversal logic using grammar-allowed characters to access unintended data. For versions 2.0 and later, this issue only occurs when the software is deployed with the non-default configuration atlas.dsl.executor.traversal=false.
Recommendations Upgrade to version 2.5.0.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-40563

Affected Products

Apache Atlas