SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63040

HIGH · CVSS 8.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Apache InLong versions prior to 2.4.0 are vulnerable due to a lack of authorization checks in the StreamSource component, allowing any authenticated user to logically delete all stream sources. This could lead to significant data loss and disruption of services for organizations relying on this functionality. Users of affected versions should prioritize upgrading to 2.4.0 or apply the recommended patch to mitigate this risk.

CVE
CVE-2026-63040
Severity
HIGH
CVSS
8.1
EPSS
0.51%
Apache GitHub

Original NVD Description

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)