THREAT OPS › Threat News › CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
CVE-2026-23904: Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
<p>Posted by Akira Ajisaka on Jul 29</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Kyuubi (org.apache.kyuubi:kyuubi-server) 1.8.0 before 1.12.0<br /> <br /> Description:<br /> <br /> Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A <br /> remote requester with network access to the proxy can cause t
Attributed threat actors
- AkiraG1024
Indicators of compromise
- CVE-2026-23904cve
Original source: https://seclists.org/oss-sec/2026/q3/318