Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities

    June 2, 2026

    Microsoft Wants to ‘Make People Addicted’ to its New AI Assistant, Internal Documents Reveal

    June 2, 2026

    Mozilla security advisory (AV26-542) – Canadian Centre for Cyber Security

    June 2, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»Alerts»VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities
    Alerts

    VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities

    adminBy adminJune 2, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Overview

    The Collibra Platform Agent contains vulnerabilities that can be chained by a remote, unauthenticated attacker to achieve remote code execution. An attacker can exploit these issues by uploading a crafted ZIP archive that writes attacker-controlled files to arbitrary locations on the server once extracted, resulting in code execution.

    Description

    Collibra Platform (CP) and Collibra Platform Self-Hosted (CPSH), an enterprise grade, cloud-based platform designed to help organizations locate, understand, trust, and manage their data assets. The Collibra Agent of CP and CPSH that is installed on the host system is an independent service that listens on different port than the web interface and have the following vulnerabilities.

    CVE-2026-10622 Privileged REST endpoints exposed under /rest/* do not properly enforce authentication or authorization. This allows a remote, unauthenticated attacker to interact with sensitive application functionality and gather information useful for further exploitation, including identifying suitable filesystem locations or application paths.
    Additionally, the web services hosting the vulnerable REST endpoint was observed to bind to all available network interfaces regardless of the setting passed to the installer script. This behavior may increase exposure in deployments where administrators believe access is restricted to specific interfaces or trusted networks.

    CVE-2026-10621 A Zip Slip vulnerability during extraction is exposed through POST /rest/restore and enables path traversal. When a ZIP archive is processed, file paths contained within the archive are not properly validated or canonicalized before extraction.
    A remote attacker can supply a crafted ZIP archive containing directory traversal sequences, such as ../, to write files outside of the intended extraction directory. This may allow attackers to write custom files to arbitrary locations on the underlying host.
    In an observed exploitation path, this arbitrary file write can be used to place a malicious JSP file into a web-accessible directory, enabling remote code execution when the file is subsequently requested over HTTP.

    Impact

    A remote, unauthenticated attacker can chain these vulnerabilities to achieve remote code execution on the affected system. An attacker who successfully exploits these issues may be able to:
    – install a persistent web shell
    – read, modify, or delete application data
    – disrupt system availability
    – potentially pivot further into surrounding environment
    Because exploitation does not require authentication, deployments reachable across public internet may be at significant risk.

    Solution

    Collibra has released the following versions to address these vulnerabilities.

    Collibra Plaform (SaaS):
    2026.05
    2026.04.5
    2026.03.4
    2026.02.6
    2025.11.7
    2025.10.9

    Collibra Platform Self Hosted (on-prem):
    2026.03 (Build 2026.03.356)
    2025.10 (Build 2025.10.399)

    Users are strongly encouraged to update to the fixed release as soon as possible. Refer to Collibra documentation and release notes for patching and deployment guidance.
    Administrators should ensure that interfaces exposing REST endpoints are not exposed to untrusted networks and should restrict access to management interfaces wherever possible.

    Acknowledgements

    Thanks to the reporter who wishes to remain anonymous. This document was written by Michael Bragg.

    VU#873170.2
    Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.

    VU#873170.1
    Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed /rest/* endpoints.

    Vendor Information

    One or more vendors are listed for this advisory. Please reference the full report for more information.

    Other Information

    CVE IDs:

    CVE-2026-10622

    CVE-2026-10621

    Date Public: 2026-06-02
    Date First Published: 2026-06-02
    Date Last Updated: 2026-06-02 14:02 UTC
    Document Revision: 4

    • About vulnerability notes
    • Contact us about this vulnerability
    • Provide a vendor statement



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft Wants to ‘Make People Addicted’ to its New AI Assistant, Internal Documents Reveal
    admin
    • Website

    Related Posts

    Alerts

    Mozilla security advisory (AV26-542) – Canadian Centre for Cyber Security

    June 2, 2026
    Alerts

    VU#265691: Appsmiths SQL Query autocomplete renderer contains a cross site scripting vulnerability

    June 2, 2026
    Alerts

    CVE-2026-45554 | THREATINT

    June 2, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    VU#873170: Collibra Agent contains improper authentication and path traversal vulnerabilities

    June 2, 2026

    Microsoft Wants to ‘Make People Addicted’ to its New AI Assistant, Internal Documents Reveal

    June 2, 2026

    Mozilla security advisory (AV26-542) – Canadian Centre for Cyber Security

    June 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.