# CVE-2026-63043

## Summary

- **CVE ID:** CVE-2026-63043
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-23
- **Published:** Aug 20, 2026
- **Last Modified:** Aug 24, 2026

## Description

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.



Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/12146 .

## Affected Products

- Apache Software Foundation — Apache InLong (2.0.0)

## References

- [CNA](https://lists.apache.org/thread/0ohn861tzd9g7nsosd6oz3of6dvhvqnk)
- [CVE](http://www.openwall.com/lists/oss-security/2026/08/20/16)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.72%
- **EPSS Percentile:** 51.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._