Back to VulnFeed / CVE-2026-40563
root@hackertop:~/vulnfeed/CVE-2026-40563#
CVE-2026-40563 MEDIUM Injection ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

Apache Atlas up to 2.3.x code injection

Atlas 17d ago Impact pending confirmation
LIFECYCLE
6.0 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability was found in Apache Atlas up to 2.3.x. It has been rated as critical. This issue affects an unknown code block. Upgrading to version 2.4.0 eliminates this vulnerability.
Root Cause Analysis
Using CWE to declare the problem leads to CWE-94. The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Impact: Impacted is confidentiality, integrity, and availability.

Countermeasure: Upgrading to version 2.4.0 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-40563 · CVSS 6.0 · Active Threat