SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-63037

CRITICAL · CVSS 9.8 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache InLong versions prior to 2.4.0 are vulnerable to an SQL injection attack in the ORDER BY clause, which could allow attackers to manipulate database queries and potentially access sensitive data. Organizations utilizing Apache InLong should prioritize upgrading to version 2.4.0 or apply the recommended patches to mitigate this risk. This vulnerability poses a significant threat to data integrity and confidentiality, making it crucial for affected users to act promptly.

CVE
CVE-2026-63037
Severity
CRITICAL
CVSS
9.8
EPSS
0.53%
Apache GitHub

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12079 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)