Path traversal in Apache Kyuubi - CVE-2026-52680

 

Path traversal in Apache Kyuubi - CVE-2026-52680

Published: August 25, 2026


Vulnerability identifier: #VU145163
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-52680
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write controlled files outside the intended upload directory.

The vulnerability exists due to path traversal in REST batch multipart upload handling when processing a client-supplied multipart filename. A remote attacker can provide a filename containing path traversal sequences to write controlled files outside the intended upload directory.

The resulting file write is subject to filesystem permissions.


Affected software

Apache Kyuubi

How to mitigate CVE-2026-52680

Install security update from vendor's website.

Apache Kyuubi - update to 1.12.0

External References

Related Security Bulletins