CVE-2026-23904 | Apache Kyuubi up to 1.11.x Engine UI proxy server-side request forgery
A vulnerability classified as critical has been found in Apache Kyuubi up to 1.11.x. Impacted is an unknown function of the component Engine UI proxy. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-23904. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More