High severity8.1NVD Advisory· Published Aug 20, 2026· Updated Aug 27, 2026
CVE-2026-63042
CVE-2026-63042
Description
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12161 .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/08/20/15nvdMailing ListThird Party Advisory
- lists.apache.org/thread/wxs4jfjkoo6rlyovhrx8bo74rfmzwbk7nvdMailing ListVendor Advisory
News mentions
1- Apache CloudStack & InLong: 25 Vulnerabilities Disclosed in Coordinated BatchVypr Intelligence · Aug 21, 2026