CVE-2024-27181: Apache Linkis

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue.

Affected products

  • Apache Linkis: before 1.6.0 (fixed in 1.6.0)

Published 2024-08-02. Last modified 2026-06-17.