SB20260824148 - Multiple vulnerabilities in Apache InLong
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-63015)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in template information access controls when handling requests for template information. A remote user can access template information to disclose sensitive information.
2) Improper access control (CVE-ID: CVE-2026-63016)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to affect operational configuration or upload non-official packages.
The vulnerability exists due to improper access control in package creation functionality when handling package creation requests. A remote user can create new packages to affect operational configuration or upload non-official packages.
3) SQL injection (CVE-ID: CVE-2026-63037)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to sql injection in the Manager OpenAPI audit alert rule list endpoint when processing the ORDER BY clause. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.
4) SQL injection (CVE-ID: CVE-2026-63038)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary sql commands.
The vulnerability exists due to improper neutralization of special elements used in an sql command in Apache InLong when processing the dbName, tableName, schemaName, and username parameters. A remote attacker can supply crafted parameter values to execute arbitrary sql commands.
5) SQL injection (CVE-ID: CVE-2026-63039)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in AuditAlertRuleService when processing user-supplied string values in SQL statements. A remote attacker can inject crafted input to execute arbitrary SQL commands.
6) Missing Authorization (CVE-ID: CVE-2026-63040)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to logically delete all stream sources.
The vulnerability exists due to improper access control in the StreamSource forceDelete functionality when handling deletion requests. A remote user can send a deletion request to logically delete all stream sources.
7) Improper access control (CVE-ID: CVE-2026-63042)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create, modify, and delete Data Node definitions.
The vulnerability exists due to improper access control in DataNode management endpoints when handling management requests. A remote user can send authenticated requests to create, modify, and delete Data Node definitions.
8) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-63044)
CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to improper control of outbound network requests in POST /api/node/testConnection when handling user-supplied connection test requests. A remote user can send a specially crafted request to perform server-side request forgery.
No administrative role is required for exploitation.
9) Path traversal (CVE-ID: CVE-2026-63043)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in Agent file source path handling when processing a user-supplied file source path. A remote attacker can supply a crafted relative path to disclose sensitive information.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=hkp9vvp41b8shx2kpkfkw27z1lovqx2k
- https://github.com/apache/inlong/pull/12093
- https://lists.apache.org/api/email.lua?id=1yzyx57blpmdnfwptwcnv0cz40qjdqqw
- https://github.com/apache/inlong/pull/12095
- https://lists.apache.org/api/email.lua?id=vxczk3c3cp6no0qk0s95xhro34fqqw4g
- https://github.com/apache/inlong/issues/12079
- https://lists.apache.org/api/email.lua?id=16m2f9jmw76j8lhloc2p97rb9ck1b1yp
- https://github.com/apache/inlong/issues/12135
- https://lists.apache.org/api/email.lua?id=mt9phz9jphs3blvo5zwcno4lfq6br8m4
- https://github.com/apache/inlong/pull/12080
- https://lists.apache.org/api/email.lua?id=ccmhs9w9v52vxb89r3b5knq9wlcml26t
- https://github.com/apache/inlong/pull/12145
- https://lists.apache.org/api/email.lua?id=6190l9f8bp0p4nvh00mpqod5vdh55som
- https://github.com/apache/inlong/pull/12161
- https://lists.apache.org/api/email.lua?id=nh8nl0tzjkkoqvfywnl6c8k9s435s7hp
- https://github.com/apache/inlong/pull/12130
- https://lists.apache.org/api/email.lua?id=vr1xbgsv14mow33yrs3onpfcwq5blqrl
- https://github.com/apache/inlong/pull/12146