CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-62392

Critical · CVSS 9.8

Apache Kylin — OS Command Injection (CWE-78)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-78

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

Search profile — drives PoC discovery

Symbols job config parametersbackend APIOS command lineJobControllerjobConfigJobServiceExecutableManagerkylin.jobshellRuntime.execProcessBuilder
Keywords CVE-2026-62392Apache KylinOS command injectionjob configcommand injectionKylin 5.0.3RCEkylin backend APIkylin job command injection
Versions: 4.x through 5.0.3

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-15T06:30:20.000Z