All CVEs
Vulnerability intelligence

CVE-2026-63038

Apache Software Foundation Apache InLong CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/issues/12135 .

CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.7%
Riskier than 51% of all CVEs · checked 2026-10-02
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Aug 20, 2026 · latest Aug 20, 2026

Coverage timeline

Related CVEs — Apache Software Foundation