CVE-2025-53648
published 2026-06-30CVE-2025-53648: SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade…
PriorityP432medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.35%
26.9th percentile
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
Users are recommended to upgrade to version 1.0.0, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | gravitino | >= 0.5.0 < 1.0.0 | 1.0.0 |
| apache_software_foundation | apache_gravitino | >= 0.5.0 < 1.0.0 | 1.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
ghsa_unreviewed·2026-06-30
CVE-2025-53648 [MEDIUM] CWE-89 SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
Users are recommended to upgrade to version 1.0.0, which fixes this issue.
VulDB
Apache Gravitino prior 1.0.0 UI privilege escalation (EUVD-2025-210372)
vuldb·2026-06-30·CVSS 5.4
CVE-2025-53648 [MEDIUM] Apache Gravitino prior 1.0.0 UI privilege escalation (EUVD-2025-210372)
A vulnerability identified as problematic has been detected in Apache Gravitino. The affected element is an unknown function of the component UI. The manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2025-53648. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published