{"id":"CVE-2026-63038","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-63038","summary":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the\ndbName,…","details":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the\ndbName, tableName, schemaName, and username parameters. \n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/issues/12135 .","published":"2026-08-20T16:17:29.760","modified":"2026-08-24T17:17:56.010","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread/79w0cfnkhs3hctv8yn861qx3qwlc3p37"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/08/20/12"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T17:17:56.010"}}