CVE-2022-33891CISA KEVEPSS p99.8%

CVE-2022-33891Apache Spark Command Injection Vulnerability

Apache / Spark

Description

Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.

Scoring

EPSS92.98% probability of exploitation · percentile 99.8% · 2026-06-17T12:03:21Z

CISA KEV entry

Added to KEV: 2023-03-07

(incoming)1

TypeTargetConfidenceTier
KEVEntryApache Spark Command Injection Vulnerabilitykev-cve-2022-338910%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apache Kylin OS Command Injection Vulnerability
CVE
CVE-2026-33844
CVE
Apache Airflow Command Injection
CVE
CVE-2025-53763
CVE
Apache HugeGraph-Server Improper Access Control Vulnerability
CVE
CVE-2025-54920
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.