oss-sec mailing list archives

CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints


From: Radhika Kundam <radhikakundam () apache org>
Date: Tue, 28 Jul 2026 17:24:58 +0000

Severity: important 

Affected versions:

- Apache Atlas (org.apache.atlas:atlas-webapp) 0.8.0 through 2.5.0

Description:

Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of 
their assigned role, to perform administrative operations.




Affect Version:
This issue affects Apache Atlas: from 0.8 through 2.5.0.


Mitigation:
Users are recommended to upgrade to version 2.6.0, which fixes the issue.

Credit:

Geo (finder)

References:

https://atlas.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-50622


Current thread: