Executive brief
Apache Kylin, an analytics engine used for processing large datasets, contains a security flaw in how it manages user permissions. An attacker with access to the system could view sensitive job information belonging to other projects that they are not authorized to see. This could lead to the exposure of internal data processing details and metadata across different business units or projects.
Technical details
An improper authorization vulnerability (CWE-280) exists in Apache Kylin's job information retrieval mechanism. The root cause is a failure to properly validate project-level permissions when a user requests job metadata. An authenticated attacker can exploit this by querying job information for projects outside of their assigned scope, potentially gaining insights into data processing workflows and metadata of other tenants. The vulnerability affects versions 4 through 5.0.3 and is resolved in version 5.0.4.
Affected products
- Apache Kylin 4 through 5.0.3
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-07-14: patched: Fixed in version 5.0.4