Junglewise Threat Intelligence

CVE-2026-63015: Apache InLong information disclosure via unauthorized template access

CVE-2026-63015 · Severity: medium · CVSS 4.3 · Published 2026-08-20

Technologies: Apache Inlong. Vendors: Apache.

Executive brief

Apache InLong is a data integration and ingestion platform. Users without proper template permissions can view sensitive template information they should not have access to, potentially exposing configuration details and data flow designs. This authorization flaw affects versions 2.0.0 through 2.3.x and is fixed in version 2.4.0.

Technical details

This vulnerability is an authorization bypass / information disclosure flaw in Apache InLong's template access control mechanism. Non-authorized users (those without template owner/responsible person status) can view template metadata and configuration information that should be restricted. The vulnerability exists in versions 2.0.0 before 2.4.0 and is classified as uncontrolled resource consumption by the advisory, though the practical impact is information disclosure. A network-accessible attacker with user-level access to InLong can enumerate and view template details without proper entitlements. The fix is available in version 2.4.0 or via cherry-pick patches (PRs #12093 and #11732).

Affected products

  • Apache InLong 2.0.0 to before 2.4.0

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Version 2.4.0 released; patches available via GitHub PRs #12093 and #11732

References

Related threats