CVE-2026-62391 | Apache Kyuubi up to 1.11.x Spark Config Alias kyuubi.session.local.dir.allowlist access control (EUVD-2026-51518)
A vulnerability categorized as critical has been discovered in Apache Kyuubi up to 1.11.x. This impacts an unknown function of the component Spark Config Alias Handler. Such manipulation of the argument kyuubi.session.local.dir.allowlist leads to improper access controls.
This vulnerability is traded as CVE-2026-62391. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More