SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-63039

CRITICAL · CVSS 9.8 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Apache InLong versions prior to 2.4.0 are vulnerable to SQL injection due to improper handling of special elements in SQL commands, allowing attackers to manipulate SQL statements. This vulnerability could lead to unauthorized data access or modification, posing a significant risk to applications relying on affected versions. Organizations using Apache InLong should prioritize upgrading to version 2.4.0 or applying the recommended patch to mitigate this risk.

CVE
CVE-2026-63039
Severity
CRITICAL
CVSS
9.8
EPSS
0.58%
Apache GitHub

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12080 .

Related CVEs

Other vulnerabilities affecting the same vendor(s)