# CVE-2026-27478

## Summary

- **CVE ID:** CVE-2026-27478
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-290, CWE-346, CWE-1390
- **Published:** Mar 11, 2026
- **Last Modified:** Mar 12, 2026

## Description

Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without validating that the issuer is a trusted identity provider.

## Affected Products

- unitycatalog — unitycatalog (<= 0.4.0)

## References

- [CNA](https://github.com/unitycatalog/unitycatalog/security/advisories/GHSA-qqcj-rghw-829x)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 8.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._