commands via ExcuteLinux.exeCmd() with no filtering or whitelist
validation.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it.
[1] https://github.com/apache/inlong/pull/12151 .
[2] https://github.com/apache/inlong/pull/12155 .
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache inlong |
|
| Vendors & Products |
Apache
Apache inlong |
Fri, 21 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1]/[2] to solve it. [1] https://github.com/apache/inlong/pull/12151 . [2] https://github.com/apache/inlong/pull/12155 . | |
| Title | Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials | |
| Weaknesses | CWE-88 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-21T08:37:57.457Z
Reserved: 2026-07-15T07:46:44.011Z
Link: CVE-2026-63046
No data.
Status : Received
Published: 2026-08-21T09:16:40.083
Modified: 2026-08-21T09:16:40.083
Link: CVE-2026-63046
No data.
OpenCVE Enrichment
Updated: 2026-08-21T11:30:03Z
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')