Improper access control in Apache Kyuubi - CVE-2026-23904
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to improper access control in the Kyuubi engine-ui proxy when processing request paths containing attacker-supplied host and port values. A remote attacker can send a specially crafted request to perform server-side request forgery.
The issue can also result in open-proxy behavior.