Critical severity9.8NVD Advisory· Published Aug 20, 2026· Updated Aug 26, 2026
CVE-2026-63038
CVE-2026-63038
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/issues/12135 .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/20/12nvdMailing ListThird Party Advisory
- lists.apache.org/thread/79w0cfnkhs3hctv8yn861qx3qwlc3p37nvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.