CVE-2026-27478CRITICAL 9.1EPSS p8.0%

CVE-2026-27478CVE-2026-27478

Description

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS0.18% probability of exploitation · percentile 8.0% · 2026-06-19T12:03:05Z
Published2026-03-11
Last modified2026-03-16

Underlying weaknesses· 3

CWE-290CWE-346CWE-1390

References

  1. https://github.com/unitycatalog/unitycatalog/security/advisories/GHSA-qqcj-rghw-829x

3

TypeTargetConfidenceTier
WeaknessWeak Authenticationcwe-13900%live
WeaknessAuthentication Bypass by Spoofingcwe-2900%live
WeaknessOrigin Validation Errorcwe-3460%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-36721
CVE
CVE-2026-22734
CVE
CVE-2026-37979
CVE
CVE-2026-37977
CVE
CVE-2026-47655
CVE
CVE-2026-37981
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.