Skip to content

Known CVE

Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution

Apache Gravitino < 1.2.1 contains a remote code execution caused by unsanitized H2 JDBC URL via testConnection API using H2's INIT parameter, letting unauthenticated attackers execute arbitrary Java code remotely, exploit requires H2 usage.

CVE-2026-41042

Critical2026CVSS 9.1CWE-20

cve2026 · apache · gravitino · rce · unauth · oast · h2 · jdbc

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website