
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-41566 is an Improper Handling of Insufficient Permissions or Privileges vulnerability (CWE-280) in Apache Kvrocks, specifically affecting the APPLYBATCH command. It affects Apache Kvrocks versions 2.8.0 through 2.15.0, and was publicly disclosed on June 24–25, 2026 via the Apache security mailing list and oss-security. The vulnerability has a CVSS v4.0 base score of 9.4 (Critical) (Apache Advisory, oss-security).
The root cause is improper permission enforcement for the APPLYBATCH command in Apache Kvrocks (CWE-280), where the software fails to correctly validate or enforce the privilege level required before executing the command. This allows a low-privileged or insufficiently authorized network user to invoke APPLYBATCH and bypass intended access controls. The vulnerability requires low privileges and passive user interaction, and is exploitable over the network without special attack conditions. The issue was reported by security researcher Qing Xu (oss-security, Apache Advisory).
Successful exploitation allows an attacker with low privileges to bypass access controls and access or manipulate data that should be restricted to authorized users, resulting in high impacts to confidentiality, integrity, and availability of both the vulnerable system and any dependent systems. The CVSS v4.0 scoring reflects high impacts across all CIA dimensions for both the vulnerable component and downstream systems. Recovery from exploitation is rated as irrecoverable, indicating potential for persistent data corruption or unauthorized data access (Apache Advisory, Feedly).
Apache has released version 2.16.0 of Kvrocks, which fixes this vulnerability; all users running versions 2.8.0 through 2.15.0 are strongly recommended to upgrade immediately. If immediate patching is not feasible, administrators should restrict network access to Kvrocks instances and implement network-level access controls (e.g., firewall rules, VPN) to limit which clients can connect to affected systems. No other official workarounds have been published (Apache Advisory, oss-security).
The vulnerability was announced on the Apache security mailing list and cross-posted to oss-security by Hulk Lin on June 25, 2026, crediting Qing Xu as the reporter. Coverage appeared on security aggregation sites including SecurityOnline and VulDB shortly after disclosure, and the CVE was noted on Bluesky by infosec community accounts. No major vendor statements or notable researcher commentary beyond the initial disclosure have been identified (oss-security, Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."