← Advisories

Apache Submarine 0.8.0 Authentication Bypass / Remote Code Execution

Critical
Advisory ID
ZSL-2026-6007
Release Date
05 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
0.8.0
CVE
N/A
Tested On
Microsoft Windows 10 (x86_64), Eclipse Temurin OpenJDK 21.0.6 (LTS)
Summary

Apache Submarine (Submarine for short) is an End-to-End Machine Learning Platform to allow data scientists to create end-to-end machine learning workflows. On Submarine, data scientists can finish each stage in the ML model lifecycle, including data exploration, data pipeline creation, model training, serving, and monitoring.

Description

Apache Submarine (retired to the Apache Attic) suffers from an authentication bypass leading to unauthenticated remote code execution. The security filter CommonFilter.isProtectedApi() treats any request whose User-Agent header matches the Python SDK pattern as not requiring authentication, and the User-Agent header is fully attacker-controlled, so any client that sets that header reaches every protected REST endpoint with no token. Through the experiment API an attacker can define the container image and command of a job, which are placed directly onto the launched Kubernetes pod, resulting in unauthenticated remote code execution on the cluster and full administrative takeover via the user-management APIs.

/server/security/common/CommonFilter.java: ------------------------------------------ 142: protected boolean isProtectedApi(HttpServletRequest httpServletRequest) { 143: // If it is called by python, temporarily passed 144: String agentHeader = httpServletRequest.getHeader(CommonConfig.AGENT_HEADER); 145: if (StringUtils.isNoneBlank(agentHeader) && agentHeader.matches(PYTHON_USER_AGENT_REGREX)) { 146: return false; 147: } 148: // Now we just verify the api 149: return isSupportedRest(httpServletRequest.getRequestURI()); 150: } ==================================================================== /server/security/common/CommonConfig.java: ------------------------------------------ 37: public static final String PYTHON_USER_AGENT_REGREX = "^OpenAPI-Generator/[\\w\\-\\.]+/python$";
Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
25.08.2026Vendor responds and will review the finding.
04.10.2026No response from the vendor.
05.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
05.10.2026Initial release