CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.
This issue affects Apache Kylin: from 4 through 5.0.3.
Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Kylinto a version that resolves this vulnerability.Fixed in 5.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62392?
CVE-2026-62392 has a critical severity level of 9.8 according to the CVSS scoring system.
How do I fix CVE-2026-62392?
To fix CVE-2026-62392, it is recommended to upgrade to Apache Kylin version 5.0.4 or later.
What type of vulnerability is CVE-2026-62392?
CVE-2026-62392 is an OS Command Injection vulnerability that allows improper inputs to be executed as OS commands.
Which versions of Apache Kylin are affected by CVE-2026-62392?
Apache Kylin versions from 4 through 5.0.3 are affected by CVE-2026-62392.
Is CVE-2026-62392 exploitable remotely?
Yes, CVE-2026-62392 can be exploited remotely due to its nature as an OS Command Injection vulnerability.