CVE-2025-61734
Java vulnerability analysis and mitigation

Overview

CVE-2025-61734 is a "Files or Directories Accessible to External Parties" vulnerability (CWE-552) in Apache Kylin, an open-source distributed OLAP engine. It allows unauthenticated remote attackers to read arbitrary files or directories that should be restricted, potentially exposing sensitive information. The vulnerability affects Apache Kylin versions 4.0.0 through 5.0.2 across multiple Maven packages including kylin-server, kylin-core-common, and related modules. It was disclosed on September 30, 2025 via the oss-security mailing list and published to NVD on October 2, 2025. The CVSS v3.1 base score is 7.5 (High) (GitHub Advisory, oss-security).

Technical details

The root cause is classified as CWE-552 (Files or Directories Accessible to External Parties), meaning Apache Kylin improperly restricts access to certain files or directories, making them reachable by unauthorized external parties over the network. The vulnerability is exploitable remotely with no authentication, no user interaction, and low attack complexity, suggesting that specific API endpoints or file-serving mechanisms in Kylin expose internal files without adequate access controls. The Apache advisory notes that deployments are safe only if Kylin's system and project admin access is strictly protected, implying that the exposure may be partially mitigated by proper administrative access controls. The issue is tracked as KYLIN-6082 and was discovered by researcher liuhuajin (oss-security, GitHub Advisory).

Impact

Successful exploitation results in a high confidentiality impact — an unauthenticated attacker can read sensitive files or directories from the Apache Kylin server, with no impact on integrity or availability. Exposed data could include configuration files, credentials, metadata, or other sensitive internal resources stored within the Kylin installation. In environments where Kylin handles large-scale analytical data, unauthorized file access could facilitate further lateral movement or privilege escalation by exposing credentials or internal network details (GitHub Advisory, oss-security).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.089% (0.018% per Feedly), placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 530546), indicating scanner-level awareness (GitHub Advisory, Feedly).

Mitigation and workarounds

Users should upgrade Apache Kylin to version 5.0.3 or later, which contains the fix for this vulnerability. As an interim measure, the Apache advisory recommends ensuring that Kylin's system and project admin access is strictly protected, as this limits the exploitability of the flaw. Additional hardening steps include implementing network segmentation to restrict access to Kylin endpoints, auditing file and directory permissions, and monitoring for unauthorized access attempts (GitHub Advisory, oss-security).

Community reactions

The vulnerability received coverage from security news outlets including SecurityOnline.info, which reported on multiple Apache Kylin vulnerabilities including authentication bypass and SSRF issues disclosed around the same time. Rewterz also published a threat advisory covering multiple Apache Kylin vulnerabilities. Community discussion was noted on Bluesky and aggregated by VulDB and Vulners shortly after disclosure. The Apache Software Foundation's disclosure via the oss-security mailing list was straightforward, characterizing the severity as "low" in the original post despite the NVD assigning a CVSS score of 7.5 (High) (oss-security, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76904CRITICAL9.8
  • Java logoJava
  • org.geotools.jdbc:gt-jdbc-postgis
NoYesAug 21, 2026
GHSA-mqjf-5f49-2fjhCRITICAL9.8
  • Java logoJava
  • org.geotools:gt-jdbc-postgis
NoYesAug 21, 2026
CVE-2026-61827HIGH8.7
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63202HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63124HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management