{"api_version":"1","generated_at":"2026-08-22T05:19:09+00:00","cve":"CVE-2026-63042","urls":{"html":"https://cve.report/CVE-2026-63042","api":"https://cve.report/api/cve/CVE-2026-63042.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-63042","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-63042"},"summary":{"title":"Apache InLong: Missing authorization on DataNode management endpoints","description":"Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12161 .","state":"PUBLISHED","assigner":"apache","published_at":"2026-08-20 16:17:30","updated_at":"2026-08-20 17:19:14"},"problem_types":["CWE-552","CWE-552 CWE-552 Files or Directories Accessible to External Parties"],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/15","name":"http://www.openwall.com/lists/oss-security/2026/08/20/15","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/wxs4jfjkoo6rlyovhrx8bo74rfmzwbk7","name":"https://lists.apache.org/thread/wxs4jfjkoo6rlyovhrx8bo74rfmzwbk7","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-63042","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63042","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache InLong","version":"affected 2.0.0 2.4.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"tonghuaroot","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"63042","cve":"CVE-2026-63042","epss":"0.001700000","percentile":"0.067990000","score_date":"2026-08-21","updated_at":"2026-08-22 00:12:49"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-08-20T17:09:20.825Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/08/20/15"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache InLong","vendor":"Apache Software Foundation","versions":[{"lessThan":"2.4.0","status":"affected","version":"2.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"tonghuaroot"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions.</p><p>This issue affects Apache InLong: from 2.0.0 before 2.4.0.</p><p></p><p><span style=\"background-color: var(--wht);\">Users are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.</span></p><p><span style=\"background-color: rgb(255, 255, 255);\">[1]&nbsp;<a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/apache/inlong/pull/12161\">https://github.com/apache/inlong/pull/12161</a>.</span></p>"}],"value":"Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12161 ."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-552","description":"CWE-552 Files or Directories Accessible to External Parties","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-20T15:50:06.733Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/wxs4jfjkoo6rlyovhrx8bo74rfmzwbk7"}],"source":{"discovery":"UNKNOWN"},"title":"Apache InLong: Missing authorization on DataNode management endpoints","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-63042","datePublished":"2026-08-20T15:50:06.733Z","dateReserved":"2026-07-15T06:22:52.859Z","dateUpdated":"2026-08-20T17:09:20.825Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-20 16:17:30","lastModifiedDate":"2026-08-20 17:19:14","problem_types":["CWE-552","CWE-552 CWE-552 Files or Directories Accessible to External Parties"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"63042","Ordinal":"1","Title":"Apache InLong: Missing authorization on DataNode management endp","CVE":"CVE-2026-63042","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"63042","Ordinal":"1","NoteData":"Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions.\n\nThis issue affects Apache InLong: from 2.0.0 before 2.4.0.\n\n\n\nUsers are advised to upgrade to Apache InLong's  2.4.0 or cherry-pick [1] to solve it.\n\n[1]  https://github.com/apache/inlong/pull/12161 .","Type":"Description","Title":"Apache InLong: Missing authorization on DataNode management endp"}]}}}