CVE-2026-41042 is a code-injection vulnerability in Apache Gravitino's gravitino-catalog-jdbc-common component before version 1.2.1. The connection-testing functionality accepts attacker-controlled H2 JDBC connection strings without sufficient restriction. An unauthenticated caller can use H2's INIT parameter to cause execution of attacker-specified actions, resulting in arbitrary Java code execution in the Gravitino server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact, self-contained Python proof-of-concept for CVE-2026-41042, targeting Apache Gravitino versions prior to 1.2.1. The repo contains only two files: a detailed README explaining the vulnerability, exploitation flow, affected endpoints, and limitations; and a single executable Python script, poc.py, which implements the exploit end-to-end using only the Python standard library. The exploit abuses Gravitino's unauthenticated catalog connection testing functionality at POST /api/metalakes/{metalake}/catalogs/testConnection. It submits a crafted CatalogCreateRequest using provider jdbc-mysql but forces the JDBC driver to org.h2.Driver and the jdbc-url to an H2 in-memory database string containing INIT=RUNSCRIPT FROM 'http://attacker/poc.sql'. Because H2 executes INIT directives during connection setup, the target fetches attacker-controlled SQL over HTTP and executes it before Gravitino's later validation fails. The PoC expects this request to return a 5xx, but treats that error as success because code execution occurs during initialization. The Python script starts a local HTTP server with two routes: /poc.sql serves the generated SQL payload, and /beacon captures exfiltrated command output. The generated SQL defines two H2 Java aliases: SHELLEXEC, which invokes Runtime.getRuntime().exec using cmd.exe /c <cmd> and captures stdout; and BEACON, which sends that stdout back to the attacker via an HTTP GET request. The script then polls for the beacon and prints the returned command output. Primary capability: unauthenticated remote command execution on the Gravitino server. Secondary capability: output exfiltration over HTTP. The README also documents a second exploitation path via POST /api/metalakes/{ml}/catalogs, where a malicious jdbc-url can be persisted and later triggered by operations such as schema enumeration. As implemented, the PoC automates only the testConnection path. Operationally, the provided code is an operational PoC rather than a framework module: it has a hardcoded Windows execution primitive (cmd.exe /c), a default local listener on 127.0.0.1:9000, and requires modification for remote callback scenarios or Linux targets. No destructive behavior or obvious fake-exploit indicators are present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVE identifier referenced only as a filename in a GitHub pull-request conversation; the content provides no vulnerability, affected-product, impact, exploitation, or remediation details.
A critical unauthenticated remote code execution vulnerability in Apache Gravitino, apparently reachable via testConnection-related API endpoints and exploitable through a crafted JDBC URL that triggers RUNSCRIPT from a remote resource.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.