PT-2026-1236 · Apache · Apache Kyuubi
Hiroki Egawa
·
Published
2026-01-05
·
Updated
2026-02-08
·
CVE-2025-66518
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Kyuubi versions 1.6.0 through 1.10.2
Description
A client with access to the Apache Kyuubi Server through Kyuubi frontend protocols can bypass the server-side configuration
kyuubi.session.local.dir.allow.list and access local files not included in the allowed list. This allows unauthorized access to local files.Recommendations
Upgrade to version 1.10.3 or a later version to resolve this issue.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kyuubi