🔐 CVE Alert

CVE-2026-63040

UNKNOWN 0.0

Apache InLong: Missing authorization in StreamSource forceDelete

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 .

CWE CWE-552
Vendor apache software foundation
Product apache inlong
Published Aug 20, 2026
Last Updated Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache inlong

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache inlong are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache InLong
2.0.0 < 2.4.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/sbqrk88cjv3r9rnqfqgn31ox4711offy openwall.com: http://www.openwall.com/lists/oss-security/2026/08/20/14

Credits

Mingrui Liu