CRITICAL 9.8 NVD
CVE-2026-52680
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker wh
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions.
This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1.
Users are recommended to upgrade to version 1.12.0, which fixes the issue.
References
- https://lists.apache.org/thread/b0qx2v8k5v4rrqsh53pb146t7so0lmrk
- http://www.openwall.com/lists/oss-security/2026/07/30/5
- https://www.openwall.com/lists/oss-security/2026/07/30/5
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-07-30 via NVD.
Risk Timeline
CVE Disclosed2026-07-30 · 4 days ago
Remediation Resources
Official Advisory
www.openwall.com/lists/oss-security/2026/07/30/5Official Advisory
www.openwall.com/lists/oss-security/2026/07/30/5Analysis & PoC
lists.apache.org/thread/b0qx2v8k5v4rrqsh53pb146t7so0lmrk
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.