Cross-site scripting in Apache Spark - CVE-2026-32773
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges in the browser.
The vulnerability exists due to cross-site scripting in the Spark History Server web interface when rendering job-supplied content. A remote user can submit a malicious Spark job containing unescaped frontend code to escalate privileges in the browser.
User interaction is required, as a higher-privileged user must log in and visit the Spark history web page.