SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62392

CRITICAL · CVSS 9.8 EPSS 1.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Apache Kylin versions 4 through 5.0.3 are vulnerable to an OS Command Injection flaw, allowing attackers to manipulate backend API job configuration parameters and execute arbitrary OS commands. This critical vulnerability, with a CVSS score of 9.8, poses significant risks to system integrity and data security. Organizations using affected versions should prioritize upgrading to version 5.0.4 to mitigate potential exploitation.

CVE
CVE-2026-62392
Severity
CRITICAL
CVSS
9.8
EPSS
1.32%
Apache

Original NVD Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)