Apache · Apache Kyuubi · CVE-2026-62391
**Name of the Vulnerable Software and Affected Versions**
Apache Kyuubi versions 1.6.0 through 1.11.x
**Description**
Clients accessing the Apache Kyuubi Server through Kyuubi frontend protocols can bypass the server-side configuration `kyuubi.session.local.dir.allowlist` by using unprefixed Spark config aliases.
**Recommendations**
Upgrade to version 1.12.0.