← Vulnerability feed

Vulnerability record · CVE-2020-1956 · published 22 May 2020

CVE-2020-1956: Apache Kylin REST API OS command injection

Apache · Kylin

Apache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated user can inject shell metacharacters and run arbitrary operating system commands on the Kylin server. This is a high-severity remote code execution flaw in a widely deployed analytics platform.

8.8 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 97% · top 0.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
17References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityRemote code execution with low privileges, a public exploit reference, CISA KEV listing and near-maximum EPSS probability make this an urgent patch target.

What it is

Apache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated user can inject shell metacharacters and run arbitrary operating system commands on the Kylin server. This is a high-severity remote code execution flaw in a widely deployed analytics platform.

Impact

An attacker with a valid low-privileged account gains arbitrary command execution as the Kylin service account, allowing data theft, lateral movement and full host compromise.

Attack surface

Reached over the network through Kylin REST endpoints that build OS commands from request parameters. The CVSS vector requires low privileges (PR:L) and no user interaction (UI:N), so any authenticated user can attempt it.

Exploitation

Listed in CISA KEV since 2022-03-25 with a required patch deadline, and EPSS 30-day probability is 0.973 (99.9th percentile). A public exploit reference is tagged in the SonarSource advisory, so exploitation is expected and active.

What to do

  • Upgrade Apache Kylin to a release after 3.0.1 that contains the vendor patch; apply the fixes referenced in the Apache Kylin commit and advisory threads.
  • If immediate upgrade is not possible, restrict network access to Kylin REST APIs to trusted hosts and disable or block the affected endpoints.
  • Enforce least privilege on Kylin accounts and remove unused or default credentials so unauthenticated or low-privileged users cannot reach the APIs.
  • Run the Kylin service under a dedicated low-privilege OS account with no shell access to limit command execution impact.
  • Monitor the Apache Kylin security mailing list and CISA KEV entry for updated guidance.

Detection

  • Inspect Kylin web and application logs for REST requests containing shell metacharacters such as ;, |, &&, $() or backticks in parameters.
  • Alert on unexpected child processes spawned by the Kylin Java process (for example sh, bash, curl, wget, nc) using EDR or process auditing.
  • Monitor outbound network connections from Kylin hosts to unusual destinations that could indicate command-and-control or data exfiltration.
  • Review authentication logs for anomalous or newly created Kylin accounts making calls to command-related REST endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-1956 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Apache Kylin OS Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2020/07/14/1 Mailing List
https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulnerability/25706 ExploitThird Party Advisory
https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf%40%3Ccommits.kylin.apache Mailing ListPatch
https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06addec6297f0320f5111d%40%3Cuser.kylin.apache.or Mailing ListMitigationVendor Advisory
https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cdev.kylin.apache.org Mailing List
https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cuser.kylin.apache.or Mailing List
https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0%40%3Ccommits.kylin.apache Mailing ListPatch
http://www.openwall.com/lists/oss-security/2020/07/14/1 Mailing List
https://community.sonarsource.com/t/apache-kylin-3-0-1-command-injection-vulnerability/25706 ExploitThird Party Advisory
https://lists.apache.org/thread.html/r021baf9d8d4ae41e8c8332c167c4fa96c91b5086563d9be55d2d7acf%40%3Ccommits.kylin.apache Mailing ListPatch
https://lists.apache.org/thread.html/r1332ef34cf8e2c0589cf44ad269fb1fb4c06addec6297f0320f5111d%40%3Cuser.kylin.apache.or Mailing ListMitigationVendor Advisory
https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cannounce.apache.org% Mailing List
https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cdev.kylin.apache.org Mailing List
https://lists.apache.org/thread.html/r250a867961cfd6e0506240a9c7eaee782d84c6ab0091c7c4bc45f3eb%40%3Cuser.kylin.apache.or Mailing List
https://lists.apache.org/thread.html/r61666760d8a4e8764b2d5fe158d8a48b569414480fbfadede574cdc0%40%3Ccommits.kylin.apache Mailing ListPatch
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1956 Third Party AdvisoryUS Government Resource

Track CVE-2020-1956 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-62390Apache kylin sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…EPSS 0.69%9.8CVE-2026-62392Apache kylin os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…EPSS 2.5%9.8CVE-2022-44621Apache kylin command injection vulnerabilityDiagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.EPSS 3.0%9.8CVE-2022-24697Apache Kylin cube designer OS command injection via config overrideApache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the va…EPSS 85%analysed9.8CVE-2021-31522Apache kylin vulnerabilityKylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…EPSS 2.9%9.8CVE-2021-45456Apache Kylin DiagnosisService project name check mismatch allows command injectionApache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell com…EPSS 89%analysed9.8CVE-2020-13925Apache kylin os command injection vulnerabilitySimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…EPSS 20%9.8CVE-2020-13926Apache kylin sql injection vulnerabilityKylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2020-1956), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.