← Vulnerability feed

Vulnerability record · CVE-2022-24697 · published 13 October 2022

CVE-2022-24697: Apache Kylin cube designer OS command injection via config override

Apache · Kylin

Apache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the value of the "-- conf=" parameter, an attacker can inject arbitrary operating system commands into the command line, achieving remote code execution. The flaw affects Kylin 2 through 2.6.5, Kylin 3 through 3.1.2, and Kylin 4 through 4.0.1.

9.8 CVSS 3.1 Critical EPSS 85% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system command into the command line parameters. This vulnerability affects Kylin 2 version 2.6.5 and earlier, Kylin 3 version 3.1.2 and earlier, and Kylin 4 version 4.0.1 and earlier.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, combined with a very high EPSS score.

What it is

Apache Kylin's cube designer lets a user overwrite system parameters in the configuration overwrites menu. By closing the single quotes around the value of the "-- conf=" parameter, an attacker can inject arbitrary operating system commands into the command line, achieving remote code execution. The flaw affects Kylin 2 through 2.6.5, Kylin 3 through 3.1.2, and Kylin 4 through 4.0.1.

Impact

An attacker can execute arbitrary operating system commands on the Kylin server, leading to full compromise of the host and any data or credentials it can reach.

Attack surface

The vulnerability is network-reachable (AV:N) with no authentication or user interaction required per the CVSS vector, and is triggered through the cube designer's configuration overwrites menu.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.84777, 99.7th percentile), indicating elevated likelihood of exploitation; references are patch and advisory links only, with no public exploit tag.

What to do

  • Upgrade Apache Kylin to a version later than 2.6.5, 3.1.2, or 4.0.1 as applicable, following the vendor patch references.
  • Restrict network access to the Kylin web interface and cube designer to trusted administrative networks.
  • Enforce strong authentication and least-privilege roles so only authorized users can reach the cube designer configuration overwrites menu.
  • Run the Kylin service under a low-privilege account to limit the impact of command execution.
  • Monitor and audit changes to cube configuration parameters for unexpected shell metacharacters.

Detection

  • Inspect Kylin logs and configuration change records for single quotes or shell metacharacters in the "-- conf=" parameter value.
  • Alert on unexpected child processes spawned by the Kylin service account (for example shells or system utilities).
  • Monitor outbound network connections originating from the Kylin server for signs of post-exploitation activity.
  • Review cube designer configuration overwrite actions for anomalous or unauthorized users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24697 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-1956Apache Kylin REST API OS command injectionApache Kylin versions 2.3.0 through 2.6.5 and 3.0.1 concatenate user input into OS commands in some RESTful APIs without validation. An authenticated…KEVEPSS 97%analysed9.8CVE-2026-62390Apache kylin sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table ca…EPSS 0.69%9.8CVE-2026-62392Apache kylin os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job…EPSS 2.5%9.8CVE-2022-44621Apache kylin command injection vulnerabilityDiagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.EPSS 3.0%9.8CVE-2021-31522Apache kylin vulnerabilityKylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apach…EPSS 2.9%9.8CVE-2021-45456Apache Kylin DiagnosisService project name check mismatch allows command injectionApache Kylin validates a user-supplied project name before using it, but DiagnosisService checks a different value than the one passed as a shell com…EPSS 89%analysed9.8CVE-2020-13925Apache kylin os command injection vulnerabilitySimilar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; whi…EPSS 20%9.8CVE-2020-13926Apache kylin sql injection vulnerabilityKylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, wh…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2022-24697), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.