Description
Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.




Affect Version:
This issue affects Apache Atlas: from 0.8 through 2.5.0.


Mitigation:
Users are recommended to upgrade to version 2.6.0, which fixes the issue.
Published: 2026-07-29
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in Apache Atlas allows any authenticated user, regardless of role, to access admin endpoints and perform administrative operations. The flaw follows CWE-862, where insufficient access control permits unauthorized actions. This can lead to configuration changes, data manipulation, or other high‑impact tasks normally reserved for administrators, effectively giving attackers elevated privileges on the affected system.

Affected Systems

Apache Atlas 0.8 through 2.5.0 are impacted. The affected products are the Apache Atlas component from the Apache Software Foundation, covering all releases in that range.

Risk and Exploitability

The CVSS score of 8.8 signals a high‑severity vulnerability. EPSS indicates a very low but nonzero exploitation probability (<1%). It is not listed in CISA KEV. Attackers would first authenticate with any valid user account, then target the vulnerable admin endpoints to elevate privileges. The official catch‑all statement in the description means that no mitigating controls are noted beyond upgrading.

Generated by OpenCVE AI on August 3, 2026 at 13:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Atlas to version 2.6.0 or later to eliminate the authorization bypass on admin endpoints.
  • Immediately revoke or re‑define any roles that grant administrative privileges to users not required to perform admin tasks, and enforce least‑privilege policies.
  • Enable and regularly review audit logging for admin endpoint access to detect any unauthorized use.

Generated by OpenCVE AI on August 3, 2026 at 13:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache atlas
Vendors & Products Apache
Apache atlas

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.
Title Apache Atlas: Missing Authorization on Admin Endpoints
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-30T03:55:13.207Z

Reserved: 2026-06-05T09:34:23.834Z

Link: CVE-2026-50622

cve-icon Vulnrichment

Updated: 2026-07-29T09:59:14.974Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T10:16:41.047

Modified: 2026-08-05T18:36:52.367

Link: CVE-2026-50622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:45:03Z

Weaknesses