{"schema_version": "1.6.1", "id": "CVE-2026-62390", "summary": "SQL Injection Vulnerability in Catalog Cache Refresh API", "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the injection to the generated SQL.\n\nThis issue affects Apache Kylin: from 4 through 5.0.3.\n\nUsers are recommended to upgrade to version 5.0.4, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "4"}, {"last_affected": "4"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/zdrj93txvdjj07f88s43d2pcg2gomvjc"}]}