CVE Explorer
CVE-2026-6213
A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-290","description":"CWE-290 Authentication bypass by spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-807","description":"CWE-807 Reliance on untrusted inputs in a security decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SparkView","vendor":"Remote Spark (https://www.remotespark.com/)","versions":[{"lessThan":"build 1122","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":10,"baseSeverity":"CRITICAL","exploitMaturity":"ATTACKED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-290","description":"CWE-290 Authentication bypass by spoofing","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-807","description":"CWE-807 Reliance on untrusted inputs in a security decision","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.remotespark.com/view/new.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:87affba2413275ccdaf2f8a6a5b5732d496d7857ab5359e0f67188c820a1b8a7 · sha256:c6fc734413d57e18… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.