← Vulnerability feed

Vulnerability record · CVE-2026-50622 · published 29 July 2026

CVE-2026-50622: Apache atlas missing authorization vulnerability

Apache · Atlas

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.

8.8 CVSS 3.1 High EPSS 0.58% · top 54.7% CWE-862 · Missing authorization
8.8CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
5 Aug 2026Last modified by NVD

Description

Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-50622 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-34271Apache atlas path traversal vulnerabilityA vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas vers…EPSS 1.4%8.1CVE-2026-40563Apache atlas code injection vulnerabilityDescription: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas exposes a DSL search endpoint that …EPSS 0.60%7.5CVE-2016-8752Apache atlas improper access control vulnerabilityApache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI…EPSS 2.1%7.5CVE-2017-3154Apache atlas information exposure vulnerabilityError responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.EPSS 2.1%7.1CVE-2024-46910Apache atlas vulnerabilityAn authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are…EPSS 0.57%6.1CVE-2020-13928Apache atlas cross-site scripting vulnerabilityApache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of th…EPSS 2.6%6.1CVE-2019-10070Apache atlas cross-site scripting vulnerabilityApache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionalityEPSS 1.8%6.1CVE-2017-3150Apache atlas cross-site scripting vulnerabilityApache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2026-50622), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.