unitycatalog CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

unitycatalog 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to unitycatalog, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-27478 Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider. [email protected] 9.1 0.02% 2026-03-11 2026-03-16
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence