Junglewise Threat Intelligence

CVE-2026-62392: Apache Kylin OS command injection in Async Query API

CVE-2026-62392 · Severity: info · CVSS 0 · Published 2026-07-14

Vendors: Apache Software Foundation.

Executive brief

Apache Kylin, an analytics engine used for processing large datasets, contains a security flaw that could allow an attacker to execute unauthorized commands on the underlying server. By sending specially crafted parameters to a backend programming interface, an attacker could potentially gain control over the system, access sensitive data, or disrupt data processing operations. Organizations using affected versions should upgrade to version 5.0.4 to mitigate this risk.

Technical details

An OS Command Injection vulnerability (CWE-78) exists in Apache Kylin versions 4 through 5.0.3. The flaw is located in a backend API, specifically related to the Async Query API, which fails to properly neutralize special elements in job configuration parameters before passing them to the OS command line. A remote attacker with access to the affected API can inject malicious commands that will be executed with the privileges of the Kylin process. The issue is addressed in version 5.0.4.

Affected products

  • Apache Software Foundation Kylin 4 through 5.0.3

Timeline

  • 2026-07-14: advisory: Initial disclosure by Apache Software Foundation
  • 2026-07-14: patched: Version 5.0.4 released to address the issue

References