VulnerabilityModified
CVE-2026-62393
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin.
MEDIUM 4.3EPSS 0.45%
Does this matter?
Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.45% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-280
- Affected
- apache/kylin
- Source
- security@apache.org
References
- https://lists.apache.org/thread/xg8dcyjw0nkq5y8dhq3r25x3rxc62x9jMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/14/6Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.