THREATOPS
THREAT OPSThreat News › CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy

CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy

medoss_secPublished 2026-07-29

<p>Posted by Akira Ajisaka on Jul 29</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Kyuubi (org.apache.kyuubi:kyuubi-server) 1.8.0 before 1.12.0<br /> <br /> Description:<br /> <br /> Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A <br /> remote requester with network access to the proxy can cause t

Attributed threat actors

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/318