Path traversal in Apache Kyuubi - CVE-2026-52680
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to write controlled files outside the intended upload directory.
The vulnerability exists due to path traversal in REST batch multipart upload handling when processing a client-supplied multipart filename. A remote attacker can provide a filename containing path traversal sequences to write controlled files outside the intended upload directory.
The resulting file write is subject to filesystem permissions.