SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-63038

CRITICAL · CVSS 9.8 EPSS 0.57%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache InLong versions prior to 2.4.0 are vulnerable to SQL injection due to improper neutralization of special elements in parameters such as dbName, tableName, schemaName, and username. This vulnerability allows attackers to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database. Organizations using affected versions should prioritize upgrading to 2.4.0 or applying the recommended fix to mitigate this risk.

CVE
CVE-2026-63038
Severity
CRITICAL
CVSS
9.8
EPSS
0.57%
Apache GitHub

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.  This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/issues/12135 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)