Apache Atlas has a Code Injection Vulnerability
High7.1CVE-2026-40563 · Published May 4, 2026 · updated May 8, 2026
### Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas. Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data. ### Affected Version: This issue affects Apache Atlas: from 0.8-incubating through 2.4.0. For affected versions >= 2.0.0, the vulnerability is only exploitable when Atlas is deployed with below non-default configuration. `atlas.dsl.executor.traversal=false` ### Mitigation: Users are recommended to upgrade to version 2.5.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.atlas:apache-atlas Maven | >= 0.8, < 2.5.0 | 2.5.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2026-40563
More atlas advisories
All atlas| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 132025 | Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user | Medium7.1 | 2.4.0 |
| Dec 142022 | Apache Atlas: zip path traversal in import functionality | High8.8 | 2.3.0 |
| Feb 102022 | Cross-site scripting in Apache Atlas | Medium6.1 | 2.1.0 |
| Jan 82020 | Stored XSS in Apache Atlas | Medium6.1 | 0.8.4+1 more |
| Aug 292017 | Apache Atlas versions 0.6.0 | High7.5 | No fix yet |
| Aug 292017 | Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies | Medium6.1 | No fix yet |