Description
Description:
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.
Affect Version:
This issue affects Apache Atlas: from 0.8 through 2.5.0.
Mitigation:
Users are recommended to upgrade to version 2.6.0, which fixes the issue.
Missing Authorization in Apache Atlas.
A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.
Affect Version:
This issue affects Apache Atlas: from 0.8 through 2.5.0.
Mitigation:
Users are recommended to upgrade to version 2.6.0, which fixes the issue.
Published:
2026-07-29
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 29 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version: This issue affects Apache Atlas: from 0.8 through 2.5.0. Mitigation: Users are recommended to upgrade to version 2.6.0, which fixes the issue. | |
| Title | Apache Atlas: Missing Authorization on Admin Endpoints | |
| Weaknesses | CWE-862 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-07-29T09:59:14.974Z
Reserved: 2026-06-05T09:34:23.834Z
Link: CVE-2026-50622
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses