{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-40563", "assignerOrgId": "f0158376-9dc2-43b6-827c-5f631a4d8d09", "state": "PUBLISHED", "assignerShortName": "apache", "dateReserved": "2026-04-14T12:05:23.666Z", "datePublished": "2026-05-04T15:17:32.511Z", "dateUpdated": "2026-05-06T13:27:03.304Z" }, "containers": { "cna": { "affected": [ { "collectionURL": "https://repo.maven.apache.org/maven2", "defaultStatus": "unaffected", "packageName": "org.apache.atlas:atlas-repository", "product": "Apache Atlas", "vendor": "Apache Software Foundation", "versions": [ { "lessThanOrEqual": "2.4.0", "status": "affected", "version": "0.8", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "value": "Khaled M. Alshammri" }, { "lang": "en", "type": "finder", "value": "qx L" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data
Affect Version:
This issue affects Apache Atlas: from 0.8 through 2.4.0.
For the affect version >= 2.0, vulnerability is only when Atlas is deployed with below non-default configuration.
atlas.dsl.executor.traversal=false