{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/apache-kyuubi-1.7.0---1.11.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Apache Kyuubi (1.7.0 - 1.11.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eApache Kyuubi versions 1.7.0 through 1.11.1 contain an unauthenticated arbitrary file write vulnerability (CVE-2026-52680) in the REST API's batch submission endpoint. The flaw exists in the \u003ccode\u003eUtils.writeToTempFile\u003c/code\u003e method within \u003ccode\u003ekyuubi-common\u003c/code\u003e, which fails to sanitize the user-supplied filename during multipart form uploads. An attacker can craft a \u003ccode\u003ePOST\u003c/code\u003e request to \u003ccode\u003e/api/v1/batches\u003c/code\u003e containing a filename with path-traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e). While the application mangles the basename by appending a suffix, attackers can target directories such as \u003ccode\u003e/etc/profile.d/\u003c/code\u003e to drop scripts that are automatically sourced by login shells. This vulnerability is particularly dangerous when Kyuubi is configured with \u003ccode\u003ekyuubi.authentication=NONE\u003c/code\u003e, which is the default setting. The exploit allows code execution as the user running the Kyuubi process, which could result in full system compromise if Kyuubi is incorrectly running with root privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify Apache Kyuubi REST interfaces reachable on TCP port 10099.\u003c/li\u003e\n\u003cli\u003eAttacker verifies the target is unauthenticated by sending a \u003ccode\u003eGET\u003c/code\u003e request to \u003ccode\u003e/api/v1/ping\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a multipart \u003ccode\u003ePOST\u003c/code\u003e request to \u003ccode\u003e/api/v1/batches\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe request includes a \u003ccode\u003ebatchRequest\u003c/code\u003e JSON payload and a \u003ccode\u003eresourceFile\u003c/code\u003e multipart part.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eresourceFile\u003c/code\u003e uses a path-traversal filename (e.g., \u003ccode\u003e../../../../../../etc/profile.d/pwn.sh\u003c/code\u003e) to escape the target directory.\u003c/li\u003e\n\u003cli\u003eThe Kyuubi process writes the malicious payload to the filesystem (e.g., \u003ccode\u003e/etc/profile.d/pwn--.sh\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eA user (or scheduled task) initiates a login shell, triggering the system to source the malicious script in \u003ccode\u003e/etc/profile.d/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe payload executes within the context of the user opening the shell, achieving remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to achieve remote code execution on the host server. The impact is significant for organizations running Kyuubi in exposed environments, as it enables full server compromise if the Kyuubi process operates with elevated privileges.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Apache Kyuubi to version 1.12.0 or later immediately to incorporate proper path normalization.\u003c/li\u003e\n\u003cli\u003eEnable authentication by setting \u003ccode\u003ekyuubi.authentication\u003c/code\u003e to a secure mechanism (e.g., KERBEROS, LDAP, or PAM) instead of the default \u003ccode\u003eNONE\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure the Kyuubi service runs with the least privilege possible; never run the service as root.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Kyuubi REST gateway (default port 10099) using network firewalls or VPNs to prevent public or untrusted network exposure.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/api/v1/batches\u003c/code\u003e that contain directory traversal patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T13:42:57Z","date_published":"2026-08-04T13:42:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kyuubi-path-traversal/","summary":"An unauthenticated path-traversal vulnerability in the Apache Kyuubi REST API (CVE-2026-52680) allows remote attackers to write arbitrary files to the filesystem, leading to remote code execution.","title":"Unauthenticated Arbitrary File Write in Apache Kyuubi REST API","url":"https://feed.craftedsignal.io/briefs/2026-08-kyuubi-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Apache Kyuubi (1.7.0 - 1.11.1)","version":"https://jsonfeed.org/version/1.1"}