logo

Collibra Platform Agent Flaws Allow Remote Code Execution Without Authentication

ID: 485d4dda-2f0e-5a2c-9ce8-ae4a90a07d1b

STIX ID: report--485d4dda-2f0e-5a2c-9ce8-ae4a90a07d1b

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Do Son

...
...

### Executive Summary: A critical threat advisory describes two vulnerabilities in the Collibra Platform Agent — unauthenticated privileged REST endpoints that fail to enforce auth (CVE-2026-10622) and a Zip Slip extraction flaw allowing directory traversal and deployment of web shells leading to root RCE (CVE-2026-10621). The flaws can be chained by remote unauthenticated actors, particularly on installations reachable from the public internet; vendor patches and network hardening are strongly recommended immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.