CVE-2025-61733: Apache Kylin: Authentication bypass
Published Sep 30, 2025
·Updated
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 4.0.0 through 5.0.2.
Users are recommended to upgrade to version 5.0.3, which fixes the issue.
Affected Software
4 affected componentsFixes available
Apache Kylin>=4.0.0<=5.0.2
maven/org.apache.kylin:kylin-core-common>=4.0.0<5.0.3
5.0.3
maven/org.apache.kylin:kylin>=4.0.0<5.0.3
5.0.3
Apache Kylin>=4.0.0<5.0.3
Event History
Oct 2, 2025
CVE Published
via MITRE·09:47 AM
Data Sourced
via MITRE·09:47 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:31 PM
Data Sourced
via GitHub·12:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-61733?
CVE-2025-61733 has been classified as a security vulnerability that allows for authentication bypass.
2
How do I fix CVE-2025-61733?
To fix CVE-2025-61733, users should upgrade Apache Kylin to version 5.0.3 or later.
3
Which versions of Apache Kylin are affected by CVE-2025-61733?
CVE-2025-61733 affects Apache Kylin versions from 4.0.0 through 5.0.2.
4
What type of vulnerability is CVE-2025-61733?
CVE-2025-61733 is classified as an authentication bypass vulnerability.
5
Who is affected by CVE-2025-61733?
Users running versions of Apache Kylin between 4.0.0 and 5.0.2 are affected by CVE-2025-61733.