Known CVE
Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution
Apache Gravitino < 1.2.1 contains a remote code execution caused by unsanitized H2 JDBC URL via testConnection API using H2's INIT parameter, letting unauthenticated attackers execute arbitrary Java code remotely, exploit requires H2 usage.
CVE-2026-41042
Critical2026CVSS 9.1CWE-20
cve2026 · apache · gravitino · rce · unauth · oast · h2 · jdbc
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website