Junglewise Threat Intelligence

CVE-2026-54226: Apache Kvrocks vulnerability in versions 2.6.0 to 2.15.0

CVE-2026-54226 · Severity: info · CVSS 6.4 · Published 2026-06-25

Technologies: Apache Software Foundation Kvrocks. Vendors: Apache, Apache Software Foundation.

Executive brief

Apache Kvrocks is an open-source database system that provides a high-performance storage solution compatible with the Redis protocol. A vulnerability in versions 2.6.0 through 2.15.0 could allow an attacker to compromise the integrity or availability of the database service. Organizations using affected versions should upgrade to version 2.16.0 to ensure their data and operations remain secure.

Technical details

A vulnerability exists in Apache Kvrocks from version 2.6.0 through 2.15.0. While the specific CWE is not detailed in the provided advisory, the CVSS 4.0 score of 6.4 indicates a network-based attack vector requiring low privileges and some user interaction. The exploit can impact the confidentiality, integrity, and availability of the system, with significant downstream impacts on subsequent systems. The issue is resolved in version 2.16.0.

Affected products

  • Apache Kvrocks 2.6.0 through 2.15.0

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References

Related threats