https://seclists.org/oss-sec/2026/q3/534: CVE-2026-63039: Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService
Published Aug 20, 2026
·Updated
Affected Software
1 affected component
Apache Inlong>=2.0.0, <2.4.0
Frequently Asked Questions
1
Which Apache InLong deployments are affected?
Apache InLong versions from 2.0.0 up to, but not including, 2.4.0 are affected.
2
What should teams do to remediate this issue?
Upgrade Apache InLong to version 2.4.0. If upgrading is not immediately possible, cherry-pick the referenced fix in pull request 12080.
3
What is required for exploitation?
The issue permits injection of a string value into an SQL statement. The provided information does not specify the required access level, attack path, or affected default configuration.