SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-63046

HIGH · CVSS 8.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Apache InLong Agent Installer's ModuleManager is vulnerable to command injection due to improper handling of argument delimiters, allowing attackers to execute arbitrary shell commands via the ExcuteLinux.exeCmd() function without proper validation. This vulnerability affects versions 2.0.0 to 2.4.0, posing a significant risk to users who have not upgraded, as it could lead to unauthorized command execution on affected systems. Organizations utilizing Apache InLong should prioritize upgrading to version 2.4.0 or apply the relevant patches to mitigate this risk.

CVE
CVE-2026-63046
Severity
HIGH
CVSS
8.8
EPSS
0.36%
Apache Linux GitHub

Original NVD Description

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it. [1]  https://github.com/apache/inlong/pull/12151 . [2]  https://github.com/apache/inlong/pull/12155 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)