CVE-2026-52680 is a path traversal vulnerability in Apache Kyuubi REST batch multipart upload handling. The vulnerable logic uses the client-supplied multipart filename when creating a temporary uploaded resource without adequately constraining the resulting path to the intended upload directory. By supplying crafted path traversal sequences in the multipart filename, a remote attacker can cause the Kyuubi server process to write attacker-controlled content to filesystem locations outside the designated temporary upload area, subject to the permissions of the running server process. The issue affects Apache Kyuubi versions 1.7.0 through 1.11.1 and is fixed in 1.12.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small standalone Python proof-of-concept exploit and a README. The exploit targets Apache Kyuubi CVE-2026-52680, an unauthenticated path-traversal arbitrary file write in the REST batch submission endpoint. The code manually constructs a multipart/form-data POST request to /api/v1/batches with two parts: a minimal JSON batchRequest object to satisfy validation and a resourceFile part whose filename is a traversal path to /etc/profile.d/pwn.sh. Because Kyuubi mangles the basename by appending a timestamp/counter, the exploit intentionally targets a glob-executed directory (/etc/profile.d/*.sh) rather than exact-name overwrite targets. The script supports two payload modes: a blind command or a bash reverse shell callback. It uses only Python standard library modules (argparse, json, urllib) and has a single entry point in exploit.py. The README documents affected versions (1.7.0-1.11.1), fixed version (1.12.0), default REST port 10099, expected HTTP 500 behavior when no Spark backend exists, and a fingerprinting request to /api/v1/ping. Overall, this is a real operational exploit for unauthenticated arbitrary file write leading to deferred code execution, potentially root if Kyuubi runs with elevated privileges and a privileged login shell later sources the dropped script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.