CVE-2025-66518Disclosure(apache / kyuubi)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-27CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kyuubi

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
kyuubi

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-08: 1Technical Details · 2026-02-08: 102-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #ApacheKyuubi CVE-2025-66518: High-Severity Flaw in Apache Kyuubi Exposes Local Server Files https://securityonline.info/cve-2025-66518-high-severity-flaw-in-apache-kyuubi-exposes-local-server-files/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a high‑severity flaw in Apache Kyuubi that exposes local server files, without providing PoC or exploit details.

    0000057
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachekyuubi---

Explore more