Code Injection in Apache Atlas - CVE-2026-40563
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose unintended data.
The vulnerability exists due to improper control of generation of code in the DSL search endpoint when processing user-supplied query strings. A remote attacker can alter Gremlin traversal logic within grammar-allowed characters to disclose unintended data.
For deployments of version 2.0 and later, the issue is exposed only when the non-default configuration atlas.dsl.executor.traversal=false is enabled.