# CVE-2025-66518

## Summary

- **CVE ID:** CVE-2025-66518
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L)
- **CWE:** CWE-27
- **Published:** Jan 5, 2026
- **Last Modified:** Mar 13, 2026

## Description

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config.

This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2.

Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache Kyuubi (1.6.0)

## References

- [CNA](https://lists.apache.org/thread/xp460bwbyzdhho34ljd4nchyt2fmhodl)
- [CVE](http://www.openwall.com/lists/oss-security/2026/01/05/1)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.05%
- **EPSS Percentile:** 62.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._