A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 23 Jan 2026 08:00:00 +0900

Type Values Removed Values Added
Description A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.
Title Authentication bypass in Aries due to misconfiguration
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Palantir

Published:

Updated: 2026-01-22T19:33:36.287Z

Reserved: 2025-12-19T12:56:08.266Z

Link: CVE-2025-68609

cve-icon Vulnrichment

Updated: 2026-01-22T19:33:31.651Z

cve-icon NVD

Status : Received

Published: 2026-01-22T19:15:53.793

Modified: 2026-01-22T19:15:53.793

Link: CVE-2025-68609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses