CVE-2026-42100

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.  The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sparxsystems:pro_cloud_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-19 14:16

Updated : 2026-06-17 10:47


NVD link : CVE-2026-42100

Mitre link : CVE-2026-42100

CVE.ORG link : CVE-2026-42100


JSON object : View

Products Affected

sparxsystems

  • pro_cloud_server
CWE
CWE-228

Improper Handling of Syntactically Invalid Structure