SQL injection in Apache Kylin - CVE-2026-62390

 

SQL injection in Apache Kylin - CVE-2026-62390

Published: August 25, 2026


Vulnerability identifier: #VU145207
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-62390
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL commands.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in the catalog cache refresh API when handling requests to refresh the table catalog. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.


Affected software

Apache Kylin

How to mitigate CVE-2026-62390

Install security update from vendor's website.

Apache Kylin - update to 5.0.4

External References

Related Security Bulletins