CVE-2026-27478 | unitycatalog Unity Catalog up to 0.4.0 Endpoint tokens authentication spoofing
A vulnerability classified as critical has been found in unitycatalog Unity Catalog up to 0.4.0. Affected by this vulnerability is an unknown functionality of the file /api/1.0/unity-control/auth/tokens of the component Endpoint. Performing a manipulation results in authentication bypass by spoofing.
This vulnerability is cataloged as CVE-2026-27478. It is possible to initiate the attack remotely. There is no exploit available.