Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.
Affect Version:
This issue affects Apache Atlas: from 0.8 through 2.5.0.
Mitigation:
Users are recommended to upgrade to version 2.6.0, which fixes the issue.
References
Configurations
No configuration.
History
29 Jul 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
29 Jul 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
29 Jul 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-29 10:16
Updated : 2026-07-30 14:54
NVD link : CVE-2026-50622
Mitre link : CVE-2026-50622
CVE.ORG link : CVE-2026-50622
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
