CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache Refresh API
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
This issue affects Apache Kylin: from 4 through 5.0.3.
Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Kylinto a version that resolves this vulnerability.Fixed in 5.0.4Patch CVE-2026-62390
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62390?
The severity of CVE-2026-62390 is rated as critical with a CVSS score of 9.8.
What type of vulnerability is CVE-2026-62390?
CVE-2026-62390 is an SQL Injection vulnerability that affects the Catalog Cache Refresh API in Apache Kylin.
How do I fix CVE-2026-62390?
To mitigate CVE-2026-62390, users should upgrade to Apache Kylin version 5.0.4 or later.
Which versions of Apache Kylin are affected by CVE-2026-62390?
CVE-2026-62390 affects Apache Kylin versions from 4 through 5.0.3.
What can an attacker achieve through CVE-2026-62390?
An attacker can exploit CVE-2026-62390 to execute arbitrary SQL commands on the database by injecting malicious SQL through the affected API.