Junglewise Threat Intelligence

CVE-2026-46751: Apache Kvrocks vulnerability in versions 2.2.0 to 2.15.0

CVE-2026-46751 · Severity: info · CVSS 5.5 · Published 2026-06-25

Technologies: Apache Software Foundation Kvrocks. Vendors: Apache Software Foundation, Apache.

Executive brief

A vulnerability has been identified in Apache Kvrocks, a distributed key-value NoSQL database. If exploited, this flaw could allow an attacker to impact the confidentiality, integrity, or availability of the data stored within the system. Organizations using affected versions should upgrade to version 2.16.0 to maintain the security of their data operations.

Technical details

A vulnerability exists in Apache Kvrocks from version 2.2.0 through 2.15.0. According to the CVSS 4.0 vector provided by the Apache Software Foundation, the attack requires low privileges (PR:L) and user interaction (UI:P), with a high complexity (AC:H). Successful exploitation can result in low impacts to local confidentiality, integrity, and availability (VC:L/VI:L/VA:L), but potentially high impacts to subsequent systems (SC:H/SI:H/SA:H). The issue is resolved in version 2.16.0.

Affected products

  • Apache Kvrocks 2.2.0 through 2.15.0

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats