CVE-2026-62390
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.
This issue affects Apache Kylin: from 4 through 5.0.3.
Users are recommended to upgrade to version 5.0.4, which fixes the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://www.openwall.com/lists/oss-security/2026/07/14/4, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62390.json, https://lists.apache.org/thread/zdrj93txvdjj07f88s43d2pcg2gomvjc, https://nvd.nist.gov/vuln/detail/CVE-2026-62390