← back
CVE-2026-41042criticalCWE-20

Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter

63Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.1epss 0.3%
from disclosure to weapon40 days
Published on NVDJul 8
1st PoC+40d
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. This issue only happens when using H2, and H2 is mainly used for testing and local development. Also, Gravitino is typically deployed in the internal environment, so the severity is low.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.