CVE-2025-68609
Authentication Bypass in Palantir Aries Allows Unauthenticated Log Access
Publication date: 2026-01-22
Last updated on: 2026-01-22
Assigner: Palantir Technologies
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| palantir | aries | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-305 | The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Palantir's Aries service allowed unauthenticated users to access log viewing and management functions on Apollo instances when using the default configuration. It bypassed both authentication and authorization checks, meaning any client on the network could view system logs and perform operations without valid credentials.
How can this vulnerability impact me? :
The vulnerability could allow unauthorized users to view sensitive system logs and perform management operations, potentially exposing confidential information and compromising system integrity and availability.