Vulnerability record · CVE-2020-1956 · published 22 May 2020
CVE-2020-1956: Apache Kylin REST API OS command injection
Apache · Kylin
Apache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated user can inject shell metacharacters and run arbitrary operating system commands on the Kylin server. This is a high-severity remote code execution flaw in a widely deployed analytics platform.
Description
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote code execution with low privileges, a public exploit reference, CISA KEV listing and near-maximum EPSS probability make this an urgent patch target.
What it is
Apache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated user can inject shell metacharacters and run arbitrary operating system commands on the Kylin server. This is a high-severity remote code execution flaw in a widely deployed analytics platform.
Impact
An attacker with a valid low-privileged account gains arbitrary command execution as the Kylin service account, allowing data theft, lateral movement and full host compromise.
Attack surface
Reached over the network through Kylin REST endpoints that build OS commands from request parameters. The CVSS vector requires low privileges (PR:L) and no user interaction (UI:N), so any authenticated user can attempt it.
Exploitation
Listed in CISA KEV since 2022-03-25 with a required patch deadline, and EPSS 30-day probability is 0.973 (99.9th percentile). A public exploit reference is tagged in the SonarSource advisory, so exploitation is expected and active.
What to do
- Upgrade Apache Kylin to a release after 3.0.1 that contains the vendor patch; apply the fixes referenced in the Apache Kylin commit and advisory threads.
- If immediate upgrade is not possible, restrict network access to Kylin REST APIs to trusted hosts and disable or block the affected endpoints.
- Enforce least privilege on Kylin accounts and remove unused or default credentials so unauthenticated or low-privileged users cannot reach the APIs.
- Run the Kylin service under a dedicated low-privilege OS account with no shell access to limit command execution impact.
- Monitor the Apache Kylin security mailing list and CISA KEV entry for updated guidance.
Detection
- Inspect Kylin web and application logs for REST requests containing shell metacharacters such as ;, |, &&, $() or backticks in parameters.
- Alert on unexpected child processes spawned by the Kylin Java process (for example sh, bash, curl, wget, nc) using EDR or process auditing.
- Monitor outbound network connections from Kylin hosts to unusual destinations that could indicate command-and-control or data exfiltration.
- Review authentication logs for anomalous or newly created Kylin accounts making calls to command-related REST endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-1956 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Apache Kylin OS Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-1956 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-1956), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.