CVE-2026-63042 - Apache InLong: Missing authorization on DataNode management endpoints
CVE ID :CVE-2026-63042
Published : Aug. 20, 2026, 3:50 p.m. | 11 minutes ago
Description :Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12161 .
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 20, 2026, 3:50 p.m. | 11 minutes ago
Description :Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12161 .
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...