https://seclists.org/oss-sec/2026/q3/535: CVE-2026-63040: Apache InLong: Missing authorization in StamSource forceDelete
Published Aug 20, 2026
·Updated
Affected Software
1 affected component
Apache Inlong>=2.0.0<2.4.0
Frequently Asked Questions
1
Does exploitation require administrative or stream-source-specific privileges?
No. The affected StreamSource operation performs no authorization check, so any authenticated user can logically delete all stream sources.
2
What should teams do if they are running an affected release?
Upgrade Apache InLong to version 2.4.0, or cherry-pick the referenced fix.