https://seclists.org/oss-sec/2026/q3/134: CVE-2026-62390: Apache Kylin: SQL Injection Vulnerability in Catalog Cache fsh API
Published Jul 14, 2026
·Updated
Affected Software
1 affected component
Apache Kylin>=4<=5.0.3
Frequently Asked Questions
1
What is the severity of CVE-2026-62390?
The severity of CVE-2026-62390 is classified as important.
2
What versions of Apache Kylin are affected by CVE-2026-62390?
CVE-2026-62390 affects Apache Kylin versions 4 through 5.0.3.
3
What type of vulnerability is CVE-2026-62390?
CVE-2026-62390 is a SQL Injection vulnerability found in the Catalog Cache fsh API of Apache Kylin.
4
How does CVE-2026-62390 affect Apache Kylin?
CVE-2026-62390 may allow an attacker to inject malicious SQL through a backend API that refreshes the table catalog.
5
How can I remediate CVE-2026-62390?
To remediate CVE-2026-62390, upgrade Apache Kylin to a version later than 5.0.3.