CVE-2025-59790

Published Nov 28, 2025

Last updated 9 months ago

Overview

Description
Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
Source
security@apache.org
NVD status
Analyzed
Products
kvrocks

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.4
Impact score
2.5
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@apache.org
CWE-269

Social media

Hype score
Not currently trending
  1. 108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806

    @BugBunny_ai

    27 Aug 2026

    4708 Impressions

    0 Retweets

    18 Likes

    6 Bookmarks

    2 Replies

    1 Quote

  2. 66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384

    @BugBunny_ai

    14 May 2026

    23006 Impressions

    42 Retweets

    319 Likes

    117 Bookmarks

    12 Replies

    3 Quotes

  3. CVE-2025-59790: Apache Kvrocks: RESET command grants admin privileges https://t.co/LKz6CYYQ48 Severity: critical CVE-2025-59792: Apache Kvrocks: MONITOR command reveals plaintext credentials to non-admins https://t.co/4jcawrDe8i Severity: important

    @oss_security

    4 Dec 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Critical Apache Kvrocks flaw (CVE-2025-59790) grants admin privileges via RESET command. Update to v2.14.0 now to prevent unauthorized access and leaks. #ApacheKvrocks #CyberSecurity #InfoSec #DatabaseSecurity https://t.co/GiIkEdWrDl

    @Daily_CyberSec

    29 Nov 2025

    255 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-59790 Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to v… https://t.co/1u4LvrtnAl

    @CVEnew

    28 Nov 2025

    281 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations