Improper access control in Apache InLong - CVE-2026-63016
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to affect operational configuration or upload non-official packages.
The vulnerability exists due to improper access control in package creation functionality when handling package creation requests. A remote user can create new packages to affect operational configuration or upload non-official packages.