Sploitus

CVE-2026-63039

2 known exploits for CVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] https://github.com/apache/inlong/pull/12080 .

Affected products
Apache Inlong
Apache Inlong
< 2.4.0
CVSS 3.1
9.8 CRITICAL
EPSS
0.4% (37th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2026-08-20
CVE-2026-63039 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-63039

Proof-of-concept code and exploit modules indexed by Sploitus