Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-10622 represents a critical authentication bypass vulnerability in Collibra Agent's REST API endpoints. An unauthenticated attacker can access privileged functionality through exposed '/rest/*' endpoints, allowing them to potentially manipulate data governance configurations, extract sensitive metadata, or escalate privileges within the platform. This vulnerability affects organizations relying on Collibra for data cataloging and governance—critical infrastructure for regulated industries handling sensitive data. The high CVSS score of 8.2 reflects the severity of unrestricted access to administrative functions without proper identity verification.
While CVE-2026-10622 doesn't map to specific MITRE ATT&CK techniques in its current advisory, Casky's platform with extended reasoning capabilities would detect the underlying attack patterns associated with Improper Authentication (CWE-287 category attacks). Practitioners using Casky's 754 security skills would identify reconnaissance activities probing for exposed endpoints (T1592: Gather Victim Identity Information), followed by exploitation attempts leveraging the authentication bypass. The platform's Claude AI would flag suspicious patterns of unauthenticated API calls accessing restricted resources, anomalous privilege escalation sequences, and lateral movement indicators suggesting post-compromise activity. Real-world detection would reveal repeated `/rest/*` requests from external sources lacking valid authentication tokens, permission grants issued without proper identity validation, and configuration changes originating from unauthenticated sessions—all critical signals for immediate containment and patching.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-10622. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation