oss-sec mailing list archives

CVE-2026-62393: Apache Kylin: Improper authorization in job information retrieval


From: Li Yang <liyang () apache org>
Date: Tue, 14 Jul 2026 03:54:13 +0000

Severity: important 

Affected versions:

- Apache Kylin 4 through 5.0.3

Description:

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in 
job information retrieval, where an attacker may get access to unauthorized jobs in other projects.

This issue affects Apache Kylin: from 4 through 5.0.3.

Users are recommended to upgrade to version 5.0.4, which fixes the issue.

This issue is being tracked as KYLIN-6090 

Credit:

Yicheng <yyc2569580673 () gmail com> (finder)
Haoran Zhao (finder)
Lei Zhang (finder)

References:

https://kylin.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-62393
https://issues.apache.org/jira/browse/KYLIN-6090


Current thread: