{
  "from_raw": "Radhika Kundam <radhikakundam@apache.org>",
  "from": "Radhika Kundam <ra...@apache.org>",
  "gravatar": "db8f630a56da5b4f935b8e63cc60b6dd",
  "to": "an...@apache.org,\n de...@atlas.apache.org",
  "subject": "CVE-2026-50622: Apache Atlas: Missing Authorization on Admin Endpoints",
  "message-id": "<81d84894-d702-59e4-d22b-ea3cfc8a9816@apache.org>",
  "mid": "6bnp7s4396osml3c0o9opno8f603qd04",
  "permalinks": [
    "6bnp7s4396osml3c0o9opno8f603qd04",
    "r17e1b248b2d4dc468c036bca42c574fd7f60c3a0a20235e1e644a2a5@<announce.apache.org>"
  ],
  "dbid": "dcc65799e5b978315fbde133cb9506b35dcb30a298669ae8492a5056fe0d6f00",
  "cc": "de...@atlas.apache.org",
  "epoch": 1785259498,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/28 17:24:58",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Atlas (org.apache.atlas:atlas-webapp) 0.8.0 through 2.5.0\n\nDescription:\n\nDescription:\nMissing Authorization\u00a0in Apache Atlas.\nA missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.\n\n\n\n\nAffect Version:\nThis issue affects Apache Atlas: from 0.8 through 2.5.0.\n\n\nMitigation:\nUsers are recommended to upgrade to version 2.6.0, which fixes the issue.\n\nCredit:\n\nGeo (finder)\n\nReferences:\n\nhttps://atlas.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-50622\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Atlas (org.apache.atlas:atlas-webapp) 0.8.0 through 2.5.0\n\nDescription:\n\nDescription:\nMissing Authorization\u00a0in Apache Atlas.\nA missing authorization v",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 2570,
  "id": "6bnp7s4396osml3c0o9opno8f603qd04"
}