Junglewise Threat Intelligence

CVE-2026-63043: Apache InLong relative path traversal in Agent

CVE-2026-63043 · Severity: high · CVSS 7.5 · Published 2026-08-20

Technologies: Apache Inlong. Vendors: Apache.

Executive brief

Apache InLong is a data integration platform used to collect and move data between systems. A path traversal vulnerability in the Agent component allows attackers to read arbitrary files from the host filesystem, potentially exposing sensitive configuration files, credentials, or other protected data.

Technical details

A relative path traversal vulnerability exists in Apache InLong's Agent component due to insufficient validation of file source paths. An attacker can craft malicious input using path traversal sequences (e.g., ../) to escape the intended directory and read arbitrary files from the Agent host filesystem. The vulnerability affects versions 2.0.0 through 2.3.x; exploitation requires network access to the Agent. The vulnerability has been patched in version 2.4.0, and users are advised to upgrade or apply the fix from https://github.com/apache/inlong/pull/12146.

Affected products

  • Apache InLong 2.0.0 to 2.3.x

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Fix available in version 2.4.0

References

Related threats