CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints
Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.
Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0.
Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Atlasto a version that resolves this vulnerability.Fixed in 2.6.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50622?
CVE-2026-50622 has a high severity rating of 8.8 according to the CVSS 3.1 scoring.
How do I fix CVE-2026-50622?
To fix CVE-2026-50622, update Apache Atlas to a version higher than 2.5.0 to ensure proper authorization on admin endpoints.
What impact does CVE-2026-50622 have on Apache Atlas?
CVE-2026-50622 allows any authenticated user to perform administrative operations without proper authorization.
Which versions of Apache Atlas are affected by CVE-2026-50622?
CVE-2026-50622 affects all versions of Apache Atlas from 0.8 up to 2.5.0.
Who is at risk due to CVE-2026-50622?
Authenticated users in Apache Atlas can exploit CVE-2026-50622 to gain unauthorized access to administrative functions.