BIT-spark-2026-32773

    Dashboard / Vulnerabilities / BIT-spark-2026-32773

    BIT-spark-2026-32773

    Published: 8 Sept 2026Last Modified: 10 Sept 2026

    Summary: Apache Spark: XSS Vulnerability in Spark Web 3.5.4

    Details: There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege escalation in browser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked as "low" since the path to exploit requires both relatively high permissions (ability to launch a Spark job) and requires tricking a user with higher permissions to log in and visit the Spark history web page. Users are encouraged to upgrade their Spark history servers to Spark 3.5.8 or later.

    Affected packages

    Package

    Name: spark

    Purl: pkg:bitnami/spark

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 3.0.0
    Fixed -3.5.8

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-spark-2026-32773 | CVE-DB