Skip to content
kylinGHSA-mr9j-4j48-xcm2

Apache Kylin Authentication Bypass Vulnerability

High7.5CVE-2025-61733 · Published Oct 2, 2025 · updated Feb 22, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
>= 4.0.0, < 5.0.35.0.3
Details and references

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-288
Also known as
CVE-2025-61733

More kylin advisories

All
DateAdvisory
Oct 22025Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
CVE-2025-61735High7.3fixed in 5.0.3
Oct 22025Apache Kylin Files or Directories Accessible to External Parties
CVE-2025-61734High7.5fixed in 5.0.3
Mar 272025Apache Kylin Code Injection via JDBC Configuration Alteration
CVE-2025-30067Lowfixed in 5.0.2
Nov 42024Apache Kylin Session Fixation vulnerability
CVE-2024-23590High9.1fixed in 5.0.0
Dec 302022Apache Kylin vulnerable to Command injection by Useless configuration
CVE-2022-43396High8.8fixed in 4.0.3
Feb 102022Authentication bypass in Apache Kylin
CVE-2020-13937Medium5.3fixed in 3.1.1, 4.0.0-beta

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.