CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4

Published Sep 1, 2026
·
Updated

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later.

This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page.

Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

Affected Software

1 affected component
Apache Spark History Server<3.5.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Spark (Spark History Server) to a version that resolves this vulnerability.

    Fixed in 3.5.8

Event History

Sep 2, 2026
CVE Published
via MITRE·10:51 AM
Data Sourced
via MITRE·10:51 AM
DescriptionWeakness
Data Sourced
via NVD·11:17 AM
DescriptionWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Spark History Server deployments running a version before 3.5.8 are affected. Exploitation requires a user who can launch a malicious Spark job and a higher-privileged user who later logs in and visits the Spark history web page.

2

What access does an attacker need?

The attacker needs relatively high permissions: the ability to launch a Spark job that can generate unescaped frontend code in the History Server. They must also persuade or otherwise cause a higher-privileged user to view the relevant history page.

3

What should be done if the History Server cannot be upgraded immediately?

The provided information recommends upgrading Spark History Server to 3.5.8 or later and does not specify an alternative mitigation. Until upgraded, limiting who can launch Spark jobs and reducing higher-privileged users' exposure to History Server pages would address the stated exploitation prerequisites.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203