


Perceptive Security
SOC/SIEM Consultancy

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parame…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 17:03:33
Source:
nvd.nist.gov
Enterprise Applications, Database & Storage, Web Technologies
CVE-2026-41042 is a vulnerability in Apache Gravitino affecting versions before 1.2.1. Unauthenticated attackers can supply a malicious H2 JDBC URL via the testConnection API, which leverages H2's INIT parameter to execute arbitrary Java code on the server. This constitutes a remote code execution (RCE) risk without requiring authentication. The vulnerability is limited to deployments using H2, which is primarily intended for testing and local development purposes. Apache Gravitino is typically deployed in internal environments, which reduces the overall exposure. The recommended remediation is to upgrade to Apache Gravitino version 1.2.1, which resolves the issue. Despite the contextual mitigations, the ability to execute arbitrary code without authentication is inherently serious.
Technical details
Mitigation steps:
Affected products:
Apache Gravitino
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41042
https://lists.apache.org/thread/vdh88wc6j5b38v65ncb111wbbnkf6bvm
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
