Remote Code Execution in Apache Kyuubi Server Due to Proxy Misconfiguration
CVE-2026-23904

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 July 2026

What is CVE-2026-23904?

The Kyuubi Engine UI proxy has significant security flaws that allow an attacker with network access to the proxy to manipulate the Kyuubi server into sending HTTP requests to arbitrary hosts. This behavior creates a server-side request forgery (SSRF) scenario, potentially opening up the backend to unwanted exposure or enumeration of confidential services. Users are advised to upgrade to version 1.12.0, where the proxy feature is disabled by default, enhancing the security posture of their deployed applications.

Affected Version(s)

Apache Kyuubi 1.8.0 < 1.12.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ĂŤcaro Torres
.