CVE-2026-62393
בינונית 4.3
תיאור (מקור, אנגלית)
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-14/8/2026
- CWE
- CWE-280
מוצרים מושפעים
apache: kylin
קישורים
- https://lists.apache.org/thread/xg8dcyjw0nkq5y8dhq3r25x3rxc62x9j Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/14/6 Mailing ListThird Party Advisory