System running
Last check: 2026-09-29 06:30:49 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-41042

Severity
CRITICAL
CVSS Score
9.1
Description

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. This issue only happens when using H2, and H2 is mainly used for testing and local development. Also, Gravitino is typically deployed in the internal environment, so the se...

PoCs for CVE-CVE-2026-41042

cve-2026-41042
General Python 0
Lulztigre 2026-08-17
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources