CVE-2026-46751
Received Received - Intake
Remote Code Execution in Apache Kvrocks

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Apache Software Foundation

Description
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
apache kvrocks From 2.2.0 (inc) to 2.15.0 (inc)
apache kvrocks 2.16.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects Apache Kvrocks versions from 2.2.0 through 2.15.0. It is a security issue that has been identified and fixed in version 2.16.0. The exact technical details of the vulnerability are not provided in the available resources.

Impact Analysis

The vulnerability has a CVSS v4.0 base score of 5.5, indicating a moderate severity. It involves network attack vector with high attack complexity and requires low privileges and user interaction. The impact includes low confidentiality, integrity, and availability impacts, but the exact consequences are not detailed. Users of affected versions may be at risk until they upgrade to version 2.16.0.

Mitigation Strategies

Users are recommended to upgrade Apache Kvrocks to version 2.16.0, which fixes the issue.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart