Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63040

Опубликовано: 20 авг. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources.

This issue affects Apache InLong: from 2.0.0 before 2.4.0.

Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.

[1]  https://github.com/apache/inlong/pull/12145 .

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:inlong:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.4.0 (исключая)

EPSS

Процентиль: 29%
0.00365
Низкий

8.1 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 8.1
github
9 дней назад

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1]  https://github.com/apache/inlong/pull/12145 .

EPSS

Процентиль: 29%
0.00365
Низкий

8.1 High

CVSS3

Дефекты

CWE-552