CVE-2026-62391CWE-22CWE-27path-traversal

CVE-2026-62391

High · published July 31, 2026

CVSS v3.1
8.1
EPSS
1%
Percentile
42.4
In the wild
Unconfirmed
What it is

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.

Users are recommended to upgrade to version 1.12.0, which fixes the issue.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00522 · 42.4th percentile
Weaknesses
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'); CWE-27 · Path Traversal: 'dir/../../filename'
Published
2026-07-31T15:17Z
Affected products (1)
ProductVersionsFixed in
apache/kyuubi≥ 1.6.0, < 1.12.01.12.0
References (1)
EPSS history
Timeline
  • 31 JUL 09:58Z
    Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
    cvelistv5