{"api_version":"1","generated_at":"2026-08-22T05:19:07+00:00","cve":"CVE-2026-63039","urls":{"html":"https://cve.report/CVE-2026-63039","api":"https://cve.report/api/cve/CVE-2026-63039.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63039","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63039"},"summary":{"title":"Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into\nthe SQL statement, enabling SQL injection.\n\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12080 .","state":"PUBLISHED","assigner":"apache","published_at":"2026-08-20 16:17:29","updated_at":"2026-08-20 17:19:14"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/13","name":"http://www.openwall.com/lists/oss-security/2026/08/20/13","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/wzpsgwcx2hxj025pcml0loxr16kl93qt","name":"https://lists.apache.org/thread/wzpsgwcx2hxj025pcml0loxr16kl93qt","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63039","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63039","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache InLong","version":"affected 2.0.0 2.4.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Andrea Cosentino","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63039","cve":"CVE-2026-63039","epss":"0.001910000","percentile":"0.090980000","score_date":"2026-08-21","updated_at":"2026-08-22 00:12:49"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-08-20T17:09:18.391Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/13"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache InLong","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.4.0","status":"affected","version":"2.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Andrea Cosentino"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. <span style=\"background-color: rgb(255, 255, 255);\">This allows an attacker to inject<span style=\"background-color: rgb(255, 255, 255);\">&nbsp;the string value into\nthe SQL statement, enabling SQL injection.</span></span><span style=\"background-color: rgb(255, 255, 255);\"><span style=\"background-color: rgb(255, 255, 255);\"><br></span></span></p><p>This issue affects Apache InLong: from 2.0.0 before 2.4.0.</p><p></p><p><span style=\"background-color: var(--wht);\">Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.</span></p><p><span style=\"background-color: rgb(255, 255, 255);\">[1] <a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/apache/inlong/pull/12080\">https://github.com/apache/inlong/pull/12080</a>.</span></p><p></p><br><br>"}],"value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into\nthe SQL statement, enabling SQL injection.\n\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12080 ."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-20T15:43:56.274Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/wzpsgwcx2hxj025pcml0loxr16kl93qt"}],"source":{"discovery":"UNKNOWN"},"title":"Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-63039","datePublished":"2026-08-20T15:43:55.637Z","dateReserved":"2026-07-15T03:48:07.408Z","dateUpdated":"2026-08-20T17:09:18.391Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-20 16:17:29","lastModifiedDate":"2026-08-20 17:19:14","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63039","Ordinal":"1","Title":"Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign","CVE":"CVE-2026-63039","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63039","Ordinal":"1","NoteData":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into\nthe SQL statement, enabling SQL injection.\n\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12080 .","Type":"Description","Title":"Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign"}]}}}