# CVE-2026-62393

## Summary

- **CVE ID:** CVE-2026-62393
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-280
- **Published:** Jul 14, 2026
- **Last Modified:** Jul 15, 2026

## Description

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized jobs in other projects.

This issue affects Apache Kylin: from 4 through 5.0.3.

Users are recommended to upgrade to version 5.0.4, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache Kylin (4)

## References

- [CNA](https://lists.apache.org/thread/xg8dcyjw0nkq5y8dhq3r25x3rxc62x9j)
- [CVE](http://www.openwall.com/lists/oss-security/2026/07/14/6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 38.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._