---
id: CVE-2024-36265
title: >-
  ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in
  Apache Submarine Server Core.


  This issue affects Apache Submarine Server Core: from 0.8.0.


  An attacker can bypass authentication by sending specially crafted REST…
summary: >-
  ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in
  Apache Submarine Server Core.


  This issue affects Apache Submarine Server Core: from 0.8.0.


  An attacker can bypass authentication by sending specially crafted REST…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: apache
product: submarine
affected:
  - submarine >= 0.8.0
published: '2024-06-12'
updated: '2026-07-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-36265'
references:
  - url: 'https://lists.apache.org/thread/prckhhst19qxof064hsm8cccxtofvflz'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2024/06/12/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.apache.org/thread/prckhhst19qxof064hsm8cccxtofvflz'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00744
epssPercentile: 0.53296
ingestedAt: '2026-07-14T11:36:44.128Z'
---

## Overview

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core.

This issue affects Apache Submarine Server Core: from 0.8.0.

An attacker can bypass authentication by sending specially crafted REST requests.

As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

## Affected

- `submarine >= 0.8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
