CVE-2026-63040
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12145 .
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 0.51%
- CWE
- CWE-552
- Published
- 2026-08-20
- Last modified
- 2026-08-24
Affected products
- Apache Software Foundation Apache InLong
Weakness type
Related vulnerabilities
- CVE-2026-68831 — Windows Defender Firewall Service Information Disclosure Vulnerability
- CVE-2026-67402 — An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs...
- CVE-2026-85175 — SiYuan before v3.8.2 TLS Private Key Disclosure via getFile
- CVE-2026-82020 — Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool
- CVE-2026-53580 — Trilium arbitrary file read and denial of service via file:// URLs in the automatic image-download feature
- CVE-2026-78051 — alexta69 MeTube Cookie File cookies.txt file access
- CVE-2026-54457 — TensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpoint
- CVE-2026-63042 — Apache InLong: Missing authorization on DataNode management endpoints