Executive brief
Unity Catalog is an open-source solution for managing data and AI assets across different platforms. A critical security flaw allows an attacker to completely impersonate any user in the system, granting them unauthorized access to sensitive data catalogs, tables, and schemas. This could lead to a total compromise of data privacy and integrity within the organization's data governance framework.
Technical details
A critical authentication bypass exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The server extracts the 'iss' (issuer) claim from incoming JSON Web Tokens (JWTs) and dynamically fetches the JWKS endpoint for signature validation without verifying if the issuer is a trusted identity provider. An attacker can host a malicious OIDC-compliant server, sign a JWT with their own private key, and set the 'sub' or 'email' claim to any target user. By providing their own server as the issuer, the attacker forces Unity Catalog to validate the signature against the attacker's public key, resulting in a valid internal access token for the impersonated user. Additionally, the implementation fails to validate the 'aud' (audience) claim. The vulnerability is patched in version 0.4.1.
Affected products
- Unity Catalog unitycatalog-server <= 0.4.0
Timeline
- 2026-03-11: disclosed: NVD publication date
- 2026-03-11: patched: Version 0.4.1 released
- 2026-05-11: advisory: GitHub Advisory published