← All Advisories

An incomplete fix for a prior Kyuubi flaw still lets clients bypass the local-directory allowlist via Spark config aliases, fixed in 1.12.0

Status: UPDATED  |  Advisory ID: CVE-2026-62391

Key Details

CVECVE-2026-62391
CVSS Score / Version8.1 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsApache kyuubi
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Exploitation prediction (EPSS)0.52% probability of exploitation in the next 30 days (43% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apachekyuubi
SubsystemsGeneral OT
SectorsMultiple

What to Know

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.

This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.

Users are recommended to upgrade to version 1.12.0, which fixes the issue.

What to Do

Monitor Apache's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-62391
Vendor advisoryhttps://lists.apache.org/thread/vo4k4nxz23kfzrpp120nsojb0vrkx4w1