SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-62393

MEDIUM · CVSS 4.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Apache Kylin versions 4 through 5.0.3 are vulnerable due to improper authorization in job information retrieval, allowing attackers to access unauthorized jobs across different projects. This could lead to unauthorized data exposure and potential manipulation of sensitive job information. Organizations using affected versions should prioritize upgrading to version 5.0.4 to mitigate this risk.

CVE
CVE-2026-62393
Severity
MEDIUM
CVSS
4.3
EPSS
0.29%
Apache

Original NVD Description

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)