A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.
History

Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Palantir
Palantir aries
Vendors & Products Palantir
Palantir aries

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window.
Title Authentication bypass in Aries due to misconfiguration
Weaknesses CWE-305
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Palantir

Published: 2026-01-22T19:06:05.914Z

Updated: 2026-01-22T19:33:36.287Z

Reserved: 2025-12-19T12:56:08.266Z

Link: CVE-2025-68609

cve-icon Vulnrichment

Updated: 2026-01-22T19:33:31.651Z

cve-icon NVD

Status : Received

Published: 2026-01-22T19:15:53.793

Modified: 2026-01-22T19:15:53.793

Link: CVE-2025-68609

cve-icon Redhat

No data.