top of page
perceptive_background_267k.jpg

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parame…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 17:03:33

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Database & Storage, Web Technologies

CVE-2026-41042 is a vulnerability in Apache Gravitino affecting versions before 1.2.1. Unauthenticated attackers can supply a malicious H2 JDBC URL via the testConnection API, which leverages H2's INIT parameter to execute arbitrary Java code on the server. This constitutes a remote code execution (RCE) risk without requiring authentication. The vulnerability is limited to deployments using H2, which is primarily intended for testing and local development purposes. Apache Gravitino is typically deployed in internal environments, which reduces the overall exposure. The recommended remediation is to upgrade to Apache Gravitino version 1.2.1, which resolves the issue. Despite the contextual mitigations, the ability to execute arbitrary code without authentication is inherently serious.

Technical details

Mitigation steps:

Affected products:

Apache Gravitino

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page