{"schema_version": "1.6.1", "id": "CVE-2026-62392", "summary": "OS Command Injection via Async Query API", "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line.\n\nThis issue affects Apache Kylin: from 4 through 5.0.3.\n\nUsers are recommended to upgrade to version 5.0.4, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "4"}, {"last_affected": "4"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/9hof8lxo3mzshsh5r77mskzqlkns09gn"}]}