SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63042

HIGH · CVSS 8.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Apache InLong versions prior to 2.4.0 are vulnerable to a security flaw that allows authenticated users to create, modify, and delete Data Node definitions, potentially leading to unauthorized access to sensitive files or directories. Organizations utilizing Apache InLong should prioritize upgrading to version 2.4.0 or apply the relevant patch to mitigate this risk.

CVE
CVE-2026-63042
Severity
HIGH
CVSS
8.1
EPSS
0.51%
Apache GitHub

Original NVD Description

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12161 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)