Collibra disclosed two critical vulnerabilities in the Collibra Platform Agent that can be chained to achieve unauthenticated remote code execution in enterprise data management environments. The issues, tracked as CVE-2026-10622 and CVE-2026-10621, affect the agent's exposed REST functionality and archive extraction process. According to the advisory and CERT/CC note VU#873170, the first flaw allows access to privileged /rest/* endpoints without proper authentication or authorization, while the second is a Zip Slip path traversal bug that can write files outside intended directories.
An attacker could use the exposed REST endpoints to map the file system and then exploit the archive extraction flaw to place a malicious JSP web shell in a web-accessible location, potentially leading to arbitrary code execution as root. The risk is heightened because the agent may bind to all network interfaces and could be reachable from the public internet. Collibra released fixes for SaaS and self-hosted deployments, advised on-premises customers to upgrade to versions 2026.03 or 2025.10, and recommended restricting REST interface exposure to trusted networks and monitoring logs for unauthorized script execution.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A threat notice reported that Collibra fixed two critical vulnerabilities, CVE-2026-10622 and CVE-2026-10621, that can be chained for unauthenticated compromise and remote code execution. The notice said SaaS and self-hosted deployments were fixed, and on-premise customers were advised to upgrade to versions 2026.03 or 2025.10.
CERT/CC published vulnerability note VU#873170 covering improper authentication and path traversal vulnerabilities in the Collibra Agent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.