CVE-2026-10622: Collibra Platform On-Prem

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints.

Affected products

  • Collibra Collibra Platform On-Prem: from 2026.03, before 2026.03.356 (fixed in 2026.03.356); from 2025.10, before 2025.10.399 (fixed in 2025.10.399)
  • Collibra Collibra Platform Saas: from 2026.04, before 2026.04.5 (fixed in 2026.04.5); from 2026.03, before 2026.03.4 (fixed in 2026.03.4); from 2026.02, before 2026.02.6 (fixed in 2026.02.6); from 2025.11, before 2025.11.7 (fixed in 2025.11.7); from 2025.10, before 2025.10.9 (fixed in 2025.10.9)

Published 2026-06-02. Last modified 2026-07-22.