High severity8.1NVD Advisory· Published Aug 20, 2026· Updated Aug 27, 2026
CVE-2026-63040
CVE-2026-63040
Description
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12145 .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/20/14nvdMailing ListThird Party Advisory
- lists.apache.org/thread/sbqrk88cjv3r9rnqfqgn31ox4711offynvdMailing ListVendor Advisory
News mentions
1- Apache CloudStack & InLong: 25 Vulnerabilities Disclosed in Coordinated BatchVypr Intelligence · Aug 21, 2026