CVE-2026-62393
MEDIUMApache Kylin: Improper authorization in job information retrieval
Title source: cnaDescription
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/xg8dcyjw0nkq5y8dhq3r25x3rxc62x9j
Scores
CVSS v3
4.3
EPSS
0.0029
EPSS Percentile
21.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-280
Status
published
Products (2)
apache/kylin
4.0.0 - 5.0.4
Apache Software Foundation/Apache Kylin
4 - 5.0.3
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026