SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-52680

CRITICAL · CVSS 9.8 EPSS 0.83%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache Kyuubi versions 1.7.0 through 1.11.1 are vulnerable due to improper handling of multipart filenames during REST batch uploads, allowing remote attackers to exploit path traversal sequences. This can lead to unauthorized file writes outside the designated upload directory, potentially compromising system integrity based on filesystem permissions. Organizations using affected versions should prioritize upgrading to version 1.12.0 to mitigate this critical vulnerability.

CVE
CVE-2026-52680
Severity
CRITICAL
CVSS
9.8
EPSS
0.83%
Apache

Original NVD Description

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)