Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
History

Tue, 06 Jan 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache kyuubi
Vendors & Products Apache
Apache kyuubi

Tue, 06 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 05 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
Description Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
Title Apache Kyuubi: Unauthorized directory access due to missing path normalization
Weaknesses CWE-27
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-05T20:27:07.472Z

Reserved: 2025-12-04T01:47:50.401Z

Link: CVE-2025-66518

cve-icon Vulnrichment

Updated: 2026-01-05T12:06:18.095Z

cve-icon NVD

Status : Received

Published: 2026-01-05T09:15:54.430

Modified: 2026-01-05T13:15:54.383

Link: CVE-2025-66518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-06T14:17:38Z