SB2026082565 - Multiple vulnerabilities in Apache Kylin
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) SQL injection (CVE-ID: CVE-2026-62390)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the catalog cache refresh API when handling requests to refresh the table catalog. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.
2) OS Command Injection (CVE-ID: CVE-2026-62392)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary operating system commands.
The vulnerability exists due to command injection in the async query backend API when processing job config parameters. A remote user can supply crafted job config parameters to execute arbitrary operating system commands.
3) Improper Authorization (CVE-ID: CVE-2026-62393)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in job information retrieval when handling requests for job information. A remote user can request job information from other projects to disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=bws1wxs9bdsmmw9p2jv0sxc4cg7ybvq5
- https://issues.apache.org/jira/browse/KYLIN-6089
- https://lists.apache.org/api/email.lua?id=4zhsr1d2h4nd8lmyr3j311df137593v8
- https://issues.apache.org/jira/browse/KYLIN-6091
- https://lists.apache.org/api/email.lua?id=8f90yzv89f6nb3rm8cmv0oq0m96hgcw9
- https://issues.apache.org/jira/browse/KYLIN-6090