CVE-2026-54226
Received Received - Intake
Remote Code Execution in Apache Kvrocks

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Apache Software Foundation

Description
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
apache kvrocks 2.16.0
apache kvrocks From 2.6.0 (inc) to 2.15.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects Apache Kvrocks versions from 2.6.0 through 2.15.0. It is a security issue that has been identified and fixed in version 2.16.0. The CVSS v4.0 base score of 6.4 indicates a moderate severity vulnerability that can be exploited remotely with low attack complexity and requires low privileges and user interaction.

Impact Analysis

The vulnerability can lead to impacts such as integrity and availability issues, as indicated by the CVSS vector which includes impacts on data integrity and system availability. Exploitation requires network access, low privileges, and user interaction, but can result in compromised data and disrupted service.

Mitigation Strategies

To mitigate this vulnerability in Apache Kvrocks, users are recommended to upgrade to version 2.16.0, which fixes the issue.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54226. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart