Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin.
This issue affects Apache Kylin: from 4.0.0 through 5.0.2.
Users are recommended to upgrade to version 5.0.3, which fixes the issue.
{
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": "2025-10-02T10:15:39Z",
"cwe_ids": [
"CWE-288"
],
"github_reviewed_at": "2025-10-02T21:07:54Z"
}