CVE-2026-62391
published 2026-07-31CVE-2026-62391: The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side…
PriorityP352high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.52%
41.9th percentile
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.
Users are recommended to upgrade to version 1.12.0, which fixes the issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | kyuubi | >= 1.6.0 < 1.12.0 | 1.12.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Kyuubi up to 1.11.x Spark Config Alias kyuubi.session.local.dir.allowlist access control (EUVD-2026-51518)
vuldb·2026-07-31·CVSS 8.1
CVE-2026-62391 [HIGH] Apache Kyuubi up to 1.11.x Spark Config Alias kyuubi.session.local.dir.allowlist access control (EUVD-2026-51518)
A vulnerability categorized as critical has been discovered in Apache Kyuubi up to 1.11.x. This impacts an unknown function of the component Spark Config Alias Handler. Such manipulation of the argument kyuubi.session.local.dir.allowlist leads to improper access controls.
This vulnerability is traded as CVE-2026-62391. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
The security fix for CVE-2025-66518 is incomplete.
ghsa_unreviewed·2026-07-31·CVSS 8.8
CVE-2026-62391 [HIGH] CWE-22 The security fix for CVE-2025-66518 is incomplete.
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.
Users are recommended to upgrade to version 1.12.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-31
Published