Palantir Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Palantir products.
Products
- com.palantir.foundry:foundry-frontend4 vulnerabilities
- Gotham3 vulnerabilities
- com.palantir.acme.gaia:gaia2 vulnerabilities
- com.palantir.comments:comments2 vulnerabilities
- com.palantir.issues:issues2 vulnerabilities
- AtlasDB1 vulnerability
- com.palantir.acme.cerberus:cerberus1 vulnerability
- com.palantir.acme:dossier-app1 vulnerability
- com.palantir.acme:gotham-default-apps-bundle1 vulnerability
- com.palantir.acme:gotham-fe-bundle1 vulnerability
- com.palantir.acme:stencil-app-bundle1 vulnerability
- com.palantir.acme:titanium-browser-app-bundle1 vulnerability
- com.palantir.apollo:autopilot1 vulnerability
- com.palantir.aries:aries1 vulnerability
- com.palantir.artifacts:artifacts1 vulnerability
- com.palantir.campaigns:campaigns1 vulnerability
- com.palantir.codeassist2:code-assist-proxy1 vulnerability
- com.palantir.compute:compute-service1 vulnerability
- com.palantir.contour:contour-dispatch1 vulnerability
- com.palantir.controlpanel:control-panel1 vulnerability
- com.palantir.foundry.jobtracker:job-tracker1 vulnerability
- com.palantir.gotham:blackbird-witchcraft1 vulnerability
- com.palantir.gotham:clips21 vulnerability
- com.palantir.gotham:external-artifacts1 vulnerability
- com.palantir.gotham:glutton1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-68609MEDIUM | Authentication bypass in Aries due to misconfigurationA vulnerability in Palantir's Aries service allowed unauthenticated access to log viewing and management functionality on Apollo instances using default configuration. The defect resulted in both authentication and authorization checks being bypassed, potentially allowing any network-accessible client to view system logs and perform operations without valid credentials. No evidence of exploitation was identified during the vulnerability window. CWE-305Jan 22, 2026 | CVSS6.6v3.1 | EPSS0.368% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files.On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked correctly with the proper security levels. The regression was traced back to a change in May 2025, which was meant to allow file uploads to be shared among different artifacts (e.g. other dossiers and presentations). On deployments configured with CBAC, the front-end would present a security picker dialog to set the security level on the uploads, thereby mitigating the issue. … CWE-863Jan 9, 2026 | CVSS3.5v3.1 | EPSS0.203% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-30971MEDIUM | Gaia unauthenticated endpointsGotham Gaia application was found to be exposing multiple unauthenticated endpoints. | CVSS6.8v3.1 | EPSS0.203% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49587CRITICAL | Glutton V1 endpoints missing authenticationGlutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users that did not have any permission to hit glutton backend directly and read/update/delete data. The affected service has been patched and automatically deployed to all Apollo-managed Gotham Instances CWE-305Dec 19, 2025 | CVSS9.1v3.1 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53710HIGH | Network boundaries not respected in certain Foundry namespaces.Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable endpoint in Foundry Container Service that executed user-controlled commands locally. CWE-653Dec 18, 2025 | CVSS7.5v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-64400MEDIUM | Insufficient permission checks when pre-enrolling users SummaryControl Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment editor has access (or belongs to) the organization that they are adding a user to. CWE-284Dec 18, 2025 | CVSS4.1v3.1 | EPSS0.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-53709MEDIUM | Access control issues impacting secure-upload serviceSecure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a small number of environments. Under specific circumstances, privileged users of secure-upload could have selected email templates not necessarily created for their enrollment when sending data upload requests. Authenticated and privileged users of one enrollment could have abused an endpoint to redirect existing submission channels to a dataset they… CWE-285Jul 10, 2025 | CVSS5.4v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49589MEDIUM | Foundry artifacts denial of serviceFoundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based on an user supplied argument (size). | CVSS6.5v3.1 | EPSS0.492% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49581MEDIUM | Access control issue impacting RV backed objectsRestricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could have allowed users that didn't have permission to see such objects to view them via Object Explorer directly. This software bug did not impact or otherwise make data available across organizational boundaries nor did it allow for data to be viewed or accessed by unauthenticated users. The affected service have been patched and automatically deployed to all Apollo-managed Foun… CWE-862Dec 2, 2024 | CVSS6.5v3.1 | EPSS0.371% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49588MEDIUM | Multiple authenticated SQL injections in oracle-sidecarMultiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections. CWE-89Nov 21, 2024 | CVSS6.8v3.1 | EPSS0.291% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30968MEDIUM | Stored XSS in gaiaOne of Gotham Gaia services was found to be vulnerable to a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker to bypass CSP and get a persistent cross site scripting payload on the stack. CWE-434Mar 12, 2024 | CVSS6.8v3.1 | EPSS0.456% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes the linter name from the default value, the renamed value may be visible to the rest of the stack’s tenants.In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed value may be visible to the rest of the stack’s tenants. CWE-862Jan 29, 2024 | CVSS3.5v3.1 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-30970MEDIUM | Gotham table and Forward App Path traversalGotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system. | CVSS6.5v3.1 | EPSS0.545% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Gotham Video Broken AuthenticationThe Gotham video-application-server service contained a race condition which would cause it to not apply certain acls new videos if the source system had not yet initialized. | CVSS2.7v3.1 | EPSS0.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-30967CRITICAL | Gotham Orbital Simulator path traversalGotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system. | CVSS9.8v3.1 | EPSS0.616% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30969HIGH | Palantir Tiles missing authentication on API endpointsThe Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints. | CVSS8.2v3.1 | EPSS0.372% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30961MEDIUM | Palantir Gotham UI bug that could lead to incorrect data classificationPalantir Gotham was found to be vulnerable to a bug where under certain circumstances, the frontend could have applied an incorrect classification to a newly created property or link. | CVSS6.5v3.1 | EPSS0.351% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30959MEDIUM | Stored XSS via javascript URI in Apollo Change Requests commentIn Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction. | CVSS4.1v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30962MEDIUM | Stored XSS in cerberus attachmentsThe Gotham Cerberus service was found to have a stored cross-site scripting (XSS) vulnerability that could have allowed an attacker with access to Gotham to launch attacks against other users. This vulnerability is resolved in Cerberus 100.230704.0-27-g031dd58 . | CVSS6.8v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30952MEDIUM | Foundry Issues reporterPath phishing by parameter injectionA security defect was discovered in Foundry Issues that enabled users to create convincing phishing links by editing the request sent when creating an Issue. This defect was resolved in Frontend release 6.228.0 . CWE-20Aug 3, 2023 | CVSS5.0v3.1 | EPSS0.437% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30950MEDIUM | CVE-2023-30950The foundry campaigns service was found to be vulnerable to an unauthenticated information disclosure in a rest endpoint | CVSS6.5v3.1 | EPSS0.412% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30958MEDIUM | DOM XSS in Developer mode dashboard via redirect GET parameterA security defect was identified in Foundry Frontend that enabled users to potentially conduct DOM XSS attacks if Foundry's CSP were to be bypassed. This defect was resolved with the release of Foundry Frontend 6.225.0. | CVSS4.7v3.1 | EPSS0.399% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30951MEDIUM | CVE-2023-30951The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE). CWE-611Aug 3, 2023 | CVSS6.3v3.1 | EPSS0.452% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30949MEDIUM | CVE-2023-30949A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the page's content, which could lead to phishing attacks. | CVSS4.3v3.1 | EPSS0.201% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30956MEDIUM | IDOR in Foundry Comments allows retrieval of attachmentsA security defect was identified in Foundry Comments that enabled a user to discover the contents of an attachment submitted to another comment if they knew the internal UUID of the target attachment. This defect was resolved with the release of Foundry Comments 2.267.0. CWE-639Jul 10, 2023 | CVSS5.3v3.1 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |