CVE-2026-57111
Last modified
CVE-2026-57111 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Helix | < 2.0.1 |
References
- https://lists.apache.org/thread/wy2yv90lvqzx46vkg35xrtfddffq9cfjMailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/07/08/11Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-57111?
How severe is CVE-2026-57111?
How do I fix CVE-2026-57111?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57104Improper neutralization of input during web page generation …9.6
- CVE-2026-57105Improper neutralization of input during web page generation …5.4
- CVE-2026-57106Server-side request forgery (ssrf) in Data Quality allows an…10
- CVE-2026-57107Improper authentication in Windows Admin Center allows an au…7.8
- CVE-2026-57108Access of resource using incompatible type ('type confusion'…7.5
- CVE-2026-5711The Post Blocks & Tools plugin for WordPress is vulnerable t…6.4
- CVE-2026-57112PraisonAI is a multi-agent teams system. From praisonaiagent…8.3
- CVE-2026-57115PraisonAI is a multi-agent teams system. Prior to praisonaia…6.5
- CVE-2026-57119PraisonAI is a multi-agent teams system. Prior to 4.6.59, th…7.5
- CVE-2026-5712This vulnerability impacts all versions of IdentityIQ and al…8.8
- CVE-2026-57120PraisonAI is a multi-agent teams system. Prior to praisonaia…6.5
- CVE-2026-57122PraisonAI is a multi-agent teams system. Prior to 4.6.59, th…8.6
Are you affected by CVE-2026-57111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
