/Vulnerability Library

Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution

CVE-2026-41042
Verified

Description

Apache Gravitino < 1.2.1 contains a remote code execution caused by unsanitized H2 JDBC URL via testConnection API using H2's INIT parameter, letting unauthenticated attackers execute arbitrary Java code remotely, exploit requires H2 usage.

Severity

Critical

CVSS Score

9.1

Exploit Probability

2%

Affected Product

gravitino

Published Date

August 18, 2026

Template Author

buzhimingdeaikun

CVE-2026-41042.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-41042
CWE ID:
cwe-20

References

https://github.com/advisories/GHSA-59xm-4m8c-g3xjhttps://lists.apache.org/thread/vdh88wc6j5b38v65ncb111wbbnkf6bvmhttps://nvd.nist.gov/vuln/detail/CVE-2026-41042

Remediation Steps

Upgrade to version 1.2.1 or later.