SQL Injection Vulnerability in Apache InLong Backend Database
CVE-2026-63037

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
20 August 2026

What is CVE-2026-63037?

An improper neutralization of special elements used in an SQL command has been identified in Apache InLong, allowing potential SQL injection attacks through the ORDER BY clause against the Manager backend database. This vulnerability affects versions of Apache InLong from 2.0.0 before 2.4.0, posing risks to database integrity and security. Users are strongly advised to upgrade to version 2.4.0 or apply necessary patches to mitigate the threat and ensure robust database protection.

Affected Version(s)

Apache InLong 2.0.0 < 2.4.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cat dg
.