CVE-2025-66518 HIGH

CVE-2025-66518: Apache Kyuubi: Unauthorized directory access due to missing path normalization

Vendor Apache Software Foundation
Product Apache Kyuubi
Weakness CWE-27
Published January 5, 2026
Last update January 5, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

What the vulnerability does

Description

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

Key dates

Disclosure timeline

January 5, 2026 CVE published
January 5, 2026 Record updated