Junglewise Threat Intelligence

CVE-2026-62390: Apache Kylin SQL injection in Catalog Cache Refresh API

CVE-2026-62390 · Severity: info · CVSS 0 · Published 2026-07-14

Vendors: Apache Software Foundation.

Executive brief

Apache Kylin, an analytics engine used for processing large datasets, contains a security vulnerability in its table catalog management. An attacker could potentially execute unauthorized database commands by exploiting a flaw in how the system refreshes its data catalog. This could lead to unauthorized access to sensitive data or disruption of the analytics platform.

Technical details

A SQL injection vulnerability exists in Apache Kylin's Catalog Cache Refresh API. The root cause is the improper neutralization of special elements used in SQL commands when the backend API refreshes the table catalog, leading to the generation of malicious SQL. The vulnerability affects versions 4 through 5.0.3. An attacker with access to the backend API could exploit this to execute arbitrary SQL commands against the underlying data store. The issue is resolved in version 5.0.4.

Affected products

  • Apache Software Foundation Kylin 4 through 5.0.3

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched: Fixed in version 5.0.4

References