VYPR
Unrated severityNVD Advisory· Published Jun 2, 2026· Updated Jun 2, 2026

CVE-2026-10622

CVE-2026-10622

Description

Collibra Agent's REST API exposes privileged functionality via unauthenticated /rest/* endpoints, allowing remote attackers to access sensitive features.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Collibra Agent's REST API exposes privileged functionality via unauthenticated /rest/* endpoints, allowing remote attackers to access sensitive features.

Vulnerability

Improper authentication in the Collibra Agent's REST API allows remote, unauthenticated attackers to access privileged functionality through exposed /rest/* endpoints. The web services hosting these endpoints may bind to all network interfaces, potentially increasing exposure beyond intended configurations. This affects Collibra Platform (CP) and Collibra Platform Self-Hosted (CPSH) agents [2].

Exploitation

An attacker can exploit this vulnerability by interacting with the exposed /rest/* endpoints without authentication. This allows them to access sensitive application functionality and gather information, such as identifying suitable filesystem locations or application paths, which can be used for further exploitation. The vulnerability can be chained with CVE-2026-10621, a Zip Slip vulnerability, to achieve remote code execution [2].

Impact

Successful exploitation allows a remote, unauthenticated attacker to access privileged functionality and gather information about the system. When chained with other vulnerabilities, such as Zip Slip, this can lead to arbitrary file writes and ultimately remote code execution on the underlying host [2].

Mitigation

Collibra has released patches for this vulnerability. Users are advised to update to the fixed versions. Specific fixed version information and release dates are available in the CERT/CC advisory [2]. Collibra's website provides general information about their platform [1].

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.