oss-sec mailing list archives

CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints


From: Charles Zhang <dockerzhang () apache org>
Date: Thu, 20 Aug 2026 14:21:31 +0000

Severity: moderate 

Affected versions:

- Apache InLong 2.0.0 before 2.4.0

Description:

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to 
the manager can create, modify and delete Data Node definitions.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.



Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/12161 .

Credit:

tonghuaroot (finder)

References:

https://inlong.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-63042


Current thread: