← Advisories

Apache SeaTunnel 3.0.0 Remote Code Execution

High
Advisory ID
ZSL-2026-6011
Release Date
07 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
3.0.0 and 2.3.13
CVE
N/A
Tested On
Microsoft Windows 10 (x86_64), Eclipse Temurin OpenJDK 21.0.6 (LTS)
Summary

SeaTunnel is a very easy-to-use, ultra-high-performance, distributed data integration platform that supports real-time synchronization of massive data. It can synchronize tens of billions of data stably and efficiently every day, and has been used in production by nearly 100 companies.

Description

Apache SeaTunnel is affected by an unauthenticated remote code execution condition in its engine REST API. The REST API v2 ships with authentication disabled by default (enable-basic-auth defaults to false), so no authentication filter is installed, and the job-submission endpoint POST /submit-job accepts a job configuration that may contain a DynamicCompile transform. That transform compiles the job-supplied source_code through an unsandboxed new GroovyClassLoader().parseClass(...) with no SecureASTCustomizer and executes it on the engine node when the transform schema is resolved. A remote party able to reach the REST port can therefore submit a single job whose Groovy (or Java/Scala) source runs arbitrary commands on the SeaTunnel engine node without any credentials.

The Apache SeaTunnel project considers this behaviour by design and declines such reports. Its security model holds that SeaTunnel is a framework that executes user-supplied code unconditionally, that any client able to reach a management interface should be treated as a cluster administrator, and that network isolation is the operator's responsibility; the project's security FAQ states that it has historically rejected numerous remote-code-execution reports on that basis. For that reason no CVE is assigned to this issue.

It remains a legitimate insecure-default weakness rather than merely an operator choice: the security-relevant control (authentication) is off in the shipped defaults, and the identical missing-authentication condition was accepted and fixed as CVE-2025-32896 on the REST API v1 endpoint one release earlier. The appropriate response is therefore hardening of the defaults - shipping with authentication required (or refusing to bind the REST API without it, or emitting a prominent startup warning), and sandboxing or gating the DynamicCompile transform for remotely submitted jobs - best pursued as a public hardening contribution (pull request) rather than a coordinated CVE.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor declined the report as out of scope under the project's published security model.
20.08.2026Replied to the vendor.
07.10.2026Public security advisory released.
Credits
Vulnerability discovered by Neurogenesia
References
Changelog
07.10.2026Initial release