CVE-2026-6213
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A
- EPSS probability
- 0.33%
- CWE
- CWE-807, CWE-290
- Published
- 2026-05-08
- Last modified
- 2026-05-11
Affected products
- Remote Spark (https://www.remotespark.com/) SparkView
Weakness type
Related vulnerabilities
- CVE-2026-87479 — Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a...
- CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
- CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)
- CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
- CVE-2026-63041 — Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
- CVE-2026-54730 — authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView
- CVE-2026-53789 — rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
- CVE-2026-64934 — Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision