Apache · Apache Inlong · CVE-2026-63040
**Name of the Vulnerable Software and Affected Versions**
Apache InLong versions 2.0.0 through 2.3.x
**Description**
An issue exists where `StreamSource` performs no authorization check, allowing any authenticated user to logically delete all stream sources.
**Recommendations**
Upgrade to version 2.4.0.