CVE-2026-62390
Critical · CVSS 9.8Apache Kylin — SQL Injection (CWE-89)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-89
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Search profile — drives PoC discovery
Symbols refreshTableCatalogtable catalogbackend APIgenerated SQLrefreshcatalog
Keywords CVE-2026-62390Apache KylinSQL injectiontable catalogrefresh catalog APIKylin SQLiKylin 5.0.3Kylin 5.0.4
Versions: 4.x through 5.0.3
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-15T06:30:20.000Z