← Vulnerability feed

Vulnerability record · CVE-2025-66518 · published 5 January 2026

CVE-2025-66518: Apache kyuubi path traversal vulnerability

Apache · Kyuubi

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

8.8 CVSS 4.0 High EPSS 1.1% · top 36.8% CWE-27 · CWE-27CWE-22 · Path traversal
8.8CVSS 4.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-66518 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-52680Apache kyuubi path traversal vulnerabilityApache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …EPSS 1.1%8.1CVE-2026-62391Apache kyuubi path traversal vulnerabilityThe security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-…EPSS 0.79%7.3CVE-2026-23904Apache kyuubi vulnerabilityKyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network a…EPSS 0.85%7.8CVE-2026-87886Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalationAcronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escal…KEVEPSS 0.23%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-23897Jenkins CLI parser arbitrary file read via @ path expansionJenkins 2.441 and earlier, and LTS 2.426.2 and earlier, fails to disable a CLI command parser feature that replaces an '@' character followed by a fi…KEVEPSS 100%analysed6.5CVE-2022-22948VMware vCenter Server information disclosure via incorrect file permissionsvCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because …KEVEPSS 13%analysed7.8CVE-2021-3493Ubuntu Linux kernel overlayfs file capability privilege escalationThe Linux kernel overlayfs implementation failed to properly validate file capability settings on files in an underlying filesystem with respect to u…KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2025-66518), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.