ID

VAR-202605-1119


CVE

CVE-2026-35194


TITLE

Apache Software Foundation of Apache Flink Code injection vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230

DESCRIPTION

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals and inject arbitrary expressions. Users are recommended to upgrade to either version 1.20.4, 2.0.2, 2.1.2 or 2.2.1, which fixes this issue. 1.20.4 , 2.0.2 , 2.1.2 or 2.2.1 We recommend that you upgrade to .All information handled by the software may be leaked to the outside. All information handled by the software may be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software

Trust: 1.62

sources: NVD: CVE-2026-35194 // JVNDB: JVNDB-2026-016230

AFFECTED PRODUCTS

vendor:apachemodel:flinkscope:eqversion:2.2.0

Trust: 1.8

vendor:apachemodel:flinkscope:gteversion:2.0.0

Trust: 1.0

vendor:apachemodel:flinkscope:gteversion:2.1.0

Trust: 1.0

vendor:apachemodel:flinkscope:gteversion:1.15.0

Trust: 1.0

vendor:apachemodel:flinkscope:ltversion:1.20.4

Trust: 1.0

vendor:apachemodel:flinkscope:ltversion:2.1.2

Trust: 1.0

vendor:apachemodel:flinkscope:ltversion:2.0.2

Trust: 1.0

vendor:apachemodel:flinkscope:eqversion:1.15.0 that's all 1.20.4

Trust: 0.8

vendor:apachemodel:flinkscope:eqversion:2.1.0 that's all 2.1.2

Trust: 0.8

vendor:apachemodel:flinkscope: - version: -

Trust: 0.8

vendor:apachemodel:flinkscope:eqversion: -

Trust: 0.8

vendor:apachemodel:flinkscope:eqversion:2.0.0 that's all 2.0.2

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230 // NVD: CVE-2026-35194

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2026-35194
value: HIGH

Trust: 1.0

OTHER: JVNDB-2026-016230
value: HIGH

Trust: 0.8

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2026-35194
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 5.2
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-016230
baseSeverity: HIGH
baseScore: 8.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230 // NVD: CVE-2026-35194

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.0

problemtype:Code injection (CWE-94) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230 // NVD: CVE-2026-35194

PATCH

title:Apache Flinkurl:https://lists.apache.org/thread/qh52bw4hhvy7n2owd8b3bt51mz0lvj9x

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230

EXTERNAL IDS

db:NVDid:CVE-2026-35194

Trust: 2.6

db:OPENWALLid:OSS-SECURITY/2026/05/15/20

Trust: 1.0

db:JVNDBid:JVNDB-2026-016230

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230 // NVD: CVE-2026-35194

REFERENCES

url:http://www.openwall.com/lists/oss-security/2026/05/15/20

Trust: 1.0

url:https://lists.apache.org/thread/qh52bw4hhvy7n2owd8b3bt51mz0lvj9x

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-35194

Trust: 0.8

sources: JVNDB: JVNDB-2026-016230 // NVD: CVE-2026-35194

SOURCES

db:JVNDBid:JVNDB-2026-016230
db:NVDid:CVE-2026-35194

LAST UPDATE DATE

2026-06-19T23:37:43.103000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-016230date:2026-05-20T04:20:00
db:NVDid:CVE-2026-35194date:2026-05-18T19:48:05.827

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-016230date:2026-05-20T00:00:00
db:NVDid:CVE-2026-35194date:2026-05-15T16:16:14.340