{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openmetadata--2.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-81029"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenMetadata (\u003c 2.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenMetadata"],"content_html":"\u003cp\u003eOpenMetadata versions prior to 2.0.0 suffer from an insecure redirect vulnerability (CVE-2026-81029) within the \u003ccode\u003eSamlLoginServlet\u003c/code\u003e, OIDC, and OAuth2 handlers. The application fails to validate the \u003ccode\u003ecallback\u003c/code\u003e request parameter before storing it in the user's HTTP session. Upon successful authentication, the server automatically appends a valid JWT - along with the user's email and name - to this attacker-supplied destination URL and performs a redirect. This flaw allows an unauthenticated attacker to craft a malicious link that, when clicked and authorized by an unsuspecting user, exfiltrates the user's session token to an external server. Once the attacker obtains this JWT, they can impersonate the victim, performing unauthorized API calls with the victim's privileges. This vulnerability impacts all 1.x releases and requires immediate remediation by upgrading to version 2.0.0 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full account takeover for the affected user. By obtaining a valid JWT, an attacker gains persistent unauthorized access to the victim's OpenMetadata account. This poses a significant risk to data integrity and confidentiality, particularly in environments where OpenMetadata integrates with sensitive organizational data stores. The number of potentially affected organizations is high, given the widespread use of OpenMetadata as an enterprise data catalog.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade OpenMetadata instances to version 2.0.0 or later immediately to remove the vulnerable caller-supplied callback parameter logic.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous outgoing redirects or suspicious outbound traffic patterns originating from the OpenMetadata server to unknown or unauthorized external domains.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering at the network level to restrict the OpenMetadata server from initiating connections to untrusted external domains.\u003c/li\u003e\n\u003cli\u003eReview all active sessions and rotate credentials for accounts identified in recent logs that match the suspicious redirect pattern.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T16:22:17Z","date_published":"2026-08-26T16:22:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openmetadata-auth-bypass/","summary":"OpenMetadata versions prior to 2.0.0 contain a critical vulnerability in the SAML, OIDC, and OAuth2 handlers that allows attackers to redirect sensitive authentication tokens to external, attacker-controlled domains.","title":"Authentication Token Theft via OpenMetadata Redirect Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-openmetadata-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenMetadata (\u003c 2.0.0)","version":"https://jsonfeed.org/version/1.1"}