PT-2026-1236 · Apache · Apache Kyuubi

Hiroki Egawa

·

Published

2026-01-05

·

Updated

2026-02-08

·

CVE-2025-66518

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Kyuubi versions 1.6.0 through 1.10.2
Description A client with access to the Apache Kyuubi Server through Kyuubi frontend protocols can bypass the server-side configuration kyuubi.session.local.dir.allow.list and access local files not included in the allowed list. This allows unauthorized access to local files.
Recommendations Upgrade to version 1.10.3 or a later version to resolve this issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-00768
CVE-2025-66518
GHSA-F8R6-6222-9PVC

Affected Products

Apache Kyuubi