Vulnerability Description
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Helix | < 2.0.1 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/wy2yv90lvqzx46vkg35xrtfddffq9cfjMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/08/11Mailing ListThird Party Advisory
FAQ
What is CVE-2026-57111?
CVE-2026-57111 is a vulnerability with a CVSS score of 7.5 (HIGH). Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker co...
How severe is CVE-2026-57111?
CVE-2026-57111 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57111?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Helix.