CVE detail
CVE-2025-61733
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. Users are recommended to upgrade to version 5.0.3, which fixes the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 11.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
2 source links · newest first
- http://www.openwall.com/lists/oss-security/2025/09/30/7www.openwall.com
No excerpt available.
Exploitwww.openwall.comOct 2, 2025, 10:15 AM - https://lists.apache.org/thread/8wmcffly6gp50nmfw8j4w3hlmv843yo0lists.apache.org
No excerpt available.
Exploitlists.apache.orgOct 2, 2025, 10:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66465CVSS 9.8 · Critical
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
- CVE-2026-66453CVSS 9.8 · Critical
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
- CVE-2026-70468CVSS 8.1 · High
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiM…
- CVE-2026-18636CVSS 6.8 · Medium
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the req…
- CVE-2026-72691CVSS 7.5 · High
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arb…
- CVE-2026-66451CVSS 6.5 · Medium
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.