CVE-2026-40563

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
04/05/2026
Last modified:
05/05/2026

Description

Description:<br /> Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache Atlas<br /> Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data<br /> <br /> <br /> <br /> <br /> Affect Version:<br /> This issue affects Apache Atlas: from 0.8 through 2.4.0.<br /> <br /> <br /> <br /> For the affect version &gt;= 2.0, vulnerability is only when Atlas is deployed with below non-default configuration.<br /> <br /> <br /> atlas.dsl.executor.traversal=false<br /> <br /> <br /> <br /> Mitigation:<br /> Users are recommended to upgrade to version 2.5.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:atlas:*:*:*:*:*:*:*:* 0.8 (including) 2.5.0 (excluding)