Remote Code Execution in Apache Kyuubi Server Due to Proxy Misconfiguration
CVE-2026-23904
Currently unrated
What is CVE-2026-23904?
The Kyuubi Engine UI proxy has significant security flaws that allow an attacker with network access to the proxy to manipulate the Kyuubi server into sending HTTP requests to arbitrary hosts. This behavior creates a server-side request forgery (SSRF) scenario, potentially opening up the backend to unwanted exposure or enumeration of confidential services. Users are advised to upgrade to version 1.12.0, where the proxy feature is disabled by default, enhancing the security posture of their deployed applications.
Affected Version(s)
Apache Kyuubi 1.8.0 < 1.12.0