With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently lead to slow database queries and expanded query coverage. This vulnerability features a low exploitation threshold, wide scope of impact, requires no external privilege escalation, and is classified as a high-priority fix.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 08:16
Updated : 2026-08-26 16:55
NVD link : CVE-2026-9668
Mitre link : CVE-2026-9668
CVE.ORG link : CVE-2026-9668
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
