Kylin
Vendor:
First CVE: Feb 24, 2020 · Active for 6 years
24
Total CVEs
More Total CVEs than 95% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 72% of tracked products
4.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Kylin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2020
6 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Kylin24 CVEs
17%
46%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (25.0%)
High1 (4.2%)
None17 (70.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1956HIGH Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute an | May 22, 2020 | 8.8 | 96 | YES | YES |
CVE-2021-45456CRITICAL Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and | Jan 6, 2022 | 9.8 | 78 | NO | NO |
CVE-2022-24697CRITICAL Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the | Oct 13, 2022 | 9.8 | 77 | NO | NO |
CVE-2020-13937MEDIUM Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.5.2, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 3.0.0-alpha, 3.0.0-alpha2, 3.0.0-beta, 3. | Oct 19, 2020 | 5.3 | 72 | NO | YES |
CVE-2022-43396HIGH In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.e | Dec 30, 2022 | 8.8 | 60 | NO | NO |
CVE-2026-62392CRITICAL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS comman | Jul 14, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-62390CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection t | Jul 14, 2026 | 9.8 | 43 | NO | NO |
CVE-2020-13925CRITICAL Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses nece | Jul 14, 2020 | 9.8 | 42 | NO | NO |
CVE-2022-44621CRITICAL Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | Dec 30, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-31522CRITICAL Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and pri | Jan 6, 2022 | 9.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
1 CVE
4.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
8.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Kylin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.0 | 5 | 8.4 | 28.2% | 0 | 1 |
| 3.1.0 | 1 | 5.3 | 78.3% | 0 | 1 |
| 3.0.2 | 1 | 5.3 | 78.3% | 0 | 1 |
| 3.0.1 | 2 | 7.0 | 87.8% | 1 | 2 |
| 3.0.0 | 3 | 7.6 | 59.5% | 1 | 2 |
| 2.6.6 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.6.5 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.6.4 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.6.3 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.6.2 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.6.1 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.6.0 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.5.2 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.5.1 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.5.0 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.4.1 | 2 | 7.0 | 87.8% | 1 | 2 |
| 2.4.0 | 2 | 7.0 | 87.8% | 1 | 2 |
| 2.3.2 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.3.1 | 1 | 5.3 | 78.3% | 0 | 1 |
| 2.3.0 | 1 | 5.3 | 78.3% | 0 | 1 |