Collibra Platform Agent Flaws Allow Remote Code Execution Without Authentication
ID: 485d4dda-2f0e-5a2c-9ce8-ae4a90a07d1b
STIX ID: report--485d4dda-2f0e-5a2c-9ce8-ae4a90a07d1b
Feed Name: securityonline.info
### Executive Summary: A critical threat advisory describes two vulnerabilities in the Collibra Platform Agent — unauthenticated privileged REST endpoints that fail to enforce auth (CVE-2026-10622) and a Zip Slip extraction flaw allowing directory traversal and deployment of web shells leading to root RCE (CVE-2026-10621). The flaws can be chained by remote unauthenticated actors, particularly on installations reachable from the public internet; vendor patches and network hardening are strongly recommended immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
