Apache · Apache Inlong · CVE-2026-63037
**Name of the Vulnerable Software and Affected Versions**
Apache InLong versions 2.0.0 through 2.3.x
**Description**
An unauthenticated SQL injection issue exists in the Manager backend database. The flaw occurs when special elements used in an SQL command are not properly neutralized in the `ORDER BY` clause of the Manager OpenAPI audit alert rule list endpoint.
**Recommendations**
Upgrade to version 2.4.0.