https://seclists.org/oss-sec/2026/q3/135: CVE-2026-62392: Apache Kylin: OS Command Injection via Async Query API
Published Jul 14, 2026
·Updated
Affected Software
1 affected component
Apache Kylin>=4<=5.0.3
Frequently Asked Questions
1
What is the severity of CVE-2026-62392?
The severity of CVE-2026-62392 is classified as important.
2
Which versions of Apache Kylin are affected by CVE-2026-62392?
Apache Kylin versions 4 through 5.0.3 are affected by CVE-2026-62392.
3
What type of vulnerability is CVE-2026-62392?
CVE-2026-62392 is an OS Command Injection vulnerability.
4
How do I fix CVE-2026-62392?
To fix CVE-2026-62392, upgrade to a patched version of Apache Kylin that addresses this vulnerability.
5
What does CVE-2026-62392 affect in Apache Kylin?
CVE-2026-62392 affects the Async Query API, allowing possible command injection through job config parameters.