PT-2026-38902 · Remote Spark · Sparkview

Manuel Feifel

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-6213

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Remote Spark SparkView versions prior to build 1122
Description An issue in the local connection check allows an attacker to bypass security restrictions and achieve arbitrary code execution as root on the server side. Depending on the implementation, this can be exploited by an unauthenticated attacker.
Recommendations Update to build 1122 or later.

Fix

RCE

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6213

Affected Products

Sparkview