CRITICAL🇵🇱 Wersja polska

CVE-2026-52680

CVSS 9.8pub. 2026-07-30upd. 2026-08-05

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Kyuubi

    APP
    Apache
    1.7.0 – 1.12.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-62391HIGH8.1PL ✓same product

Apache Kyuubi: niekompletna poprawka path traversal (bypass allowlist)

CVE-2026-23904HIGH7.3PL ✓same product

Apache Kyuubi Engine UI Proxy — podatność SSRF / open-proxy

CVE-2025-66518HIGH8.8same product

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config ...

CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor

Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same vendor

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację