CVE 6.6 MEDIUM

Authentication bypass in Aries due to misconfiguration_CVE-2025-68609

6.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.

Basic Information

ID CVE-2025-68609
Source Palantir
Published Jan 22, 2026 at 19:06
Modified Jan 22, 2026 at 19:33

Affected Product

Vendor Palantir
Product com.palantir.aries:aries
Version 1.554.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.