Home

Description

Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.

PUBLISHED Reserved 2025-09-21 | Published 2025-11-28 | Updated 2025-11-28 | Assigner apache

Problem types

CWE-269 Improper Privilege Management

Product status

Default status
unaffected

2.9.0 (semver)
affected

Credits

Mapta / BugBunny_ai reporter

References

www.openwall.com/lists/oss-security/2025/11/28/2

lists.apache.org/thread/dlbz5hmm4ts3npzqnvhofxmqg9w9zt0o vendor-advisory

cve.org (CVE-2025-59790)

nvd.nist.gov (CVE-2025-59790)

Download JSON