{"schema_version": "1.6.1", "id": "CVE-2026-50622", "summary": "Missing Authorization on Admin Endpoints", "details": "Description:\nMissing Authorization in Apache Atlas.\nA missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations.\n\n\n\n\nAffect Version:\nThis issue affects Apache Atlas: from 0.8 through 2.5.0.\n\n\nMitigation:\nUsers are recommended to upgrade to version 2.6.0, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "0.8.0"}, {"last_affected": "0.8.0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/6r9vs7g5gkp983pwvky781hofdozhgzn"}]}