Description
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
Published: 2026-05-08
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Customer can also set trustLocal = false in the gateway.conf as a workaround for this problem if they cannot update to build 1122 or later.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Sun, 10 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Remote Spark
Remote Spark sparkview
Vendors & Products Remote Spark
Remote Spark sparkview

Fri, 08 May 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 May 2026 09:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
Title Remote Spark SparkView RCE
Weaknesses CWE-290
CWE-807
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A'}


Subscriptions

Remote Spark Sparkview
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-05-11T07:48:23.801Z

Reserved: 2026-04-13T12:27:34.073Z

Link: CVE-2026-6213

cve-icon Vulnrichment

Updated: 2026-05-08T12:45:02.451Z

cve-icon NVD

Status : Deferred

Published: 2026-05-08T10:16:29.270

Modified: 2026-05-08T15:51:08.590

Link: CVE-2026-6213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-10T21:26:02Z

Weaknesses