SB20260824148 - Multiple vulnerabilities in Apache InLong



SB20260824148 - Multiple vulnerabilities in Apache InLong

Published: August 24, 2026

Security Bulletin ID SB20260824148
CSH Severity
High
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 22% Medium 22% Low 56%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-63015)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in template information access controls when handling requests for template information. A remote user can access template information to disclose sensitive information.


2) Improper access control (CVE-ID: CVE-2026-63016)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to affect operational configuration or upload non-official packages.

The vulnerability exists due to improper access control in package creation functionality when handling package creation requests. A remote user can create new packages to affect operational configuration or upload non-official packages.


3) SQL injection (CVE-ID: CVE-2026-63037)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary SQL commands.

The vulnerability exists due to sql injection in the Manager OpenAPI audit alert rule list endpoint when processing the ORDER BY clause. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.


4) SQL injection (CVE-ID: CVE-2026-63038)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary sql commands.

The vulnerability exists due to improper neutralization of special elements used in an sql command in Apache InLong when processing the dbName, tableName, schemaName, and username parameters. A remote attacker can supply crafted parameter values to execute arbitrary sql commands.


5) SQL injection (CVE-ID: CVE-2026-63039)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary SQL commands.

The vulnerability exists due to SQL injection in AuditAlertRuleService when processing user-supplied string values in SQL statements. A remote attacker can inject crafted input to execute arbitrary SQL commands.


6) Missing Authorization (CVE-ID: CVE-2026-63040)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to logically delete all stream sources.

The vulnerability exists due to improper access control in the StreamSource forceDelete functionality when handling deletion requests. A remote user can send a deletion request to logically delete all stream sources.


7) Improper access control (CVE-ID: CVE-2026-63042)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to create, modify, and delete Data Node definitions.

The vulnerability exists due to improper access control in DataNode management endpoints when handling management requests. A remote user can send authenticated requests to create, modify, and delete Data Node definitions.


8) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-63044)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform server-side request forgery.

The vulnerability exists due to improper control of outbound network requests in POST /api/node/testConnection when handling user-supplied connection test requests. A remote user can send a specially crafted request to perform server-side request forgery.

No administrative role is required for exploitation.


9) Path traversal (CVE-ID: CVE-2026-63043)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in Agent file source path handling when processing a user-supplied file source path. A remote attacker can supply a crafted relative path to disclose sensitive information.


Remediation

Install update from vendor's website.