CVE-2026-62393: Apache Kylin
Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Affected products
- Apache Kylin: from 4.0.0, before 5.0.4 (fixed in 5.0.4)
Published 2026-07-14. Last modified 2026-07-15.