CVE-2026-50006
Last modified
CVE-2026-50006 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the Anyquery server process, cause SQLite to create a database file there, and place attacker-controlled table content in that file. This permits arbitrary file creation or overwrite, causing filesystem integrity loss and denial of service; remote code execution is possible only when another service interprets the written file or the process has a suitably privileged writable target. This issue is fixed in version 0.4.5.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| julien040 | anyquery | < 0.4.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-50006?
How severe is CVE-2026-50006?
How do I fix CVE-2026-50006?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49996SecureDrop Client is a desktop app for journalists to secure…3.7
- CVE-2026-49997SurrealDB is a scalable, distributed, collaborative, documen…5.4
- CVE-2026-49998Centrifugo is an open-source scalable real-time messaging se…8.2
- CVE-2026-5000A vulnerability was detected in PromtEngineer localGPT up to…7.3
- CVE-2026-50003A malicious or compromised server can make a DCMTK client us…9.8
- CVE-2026-50005Brickcom cameras ship with default credentials that allows a…8.3
- CVE-2026-50007Actual is an open-source personal finance application. Prior…7.2
- CVE-2026-50008Parse Server is an open source backend that can be deployed …6.9
- CVE-2026-50009Netty is a network application framework for development of …4.8
- CVE-2026-5001A flaw has been found in PromtEngineer localGPT up to 4d41c7…7.3
- CVE-2026-50010Netty is a network application framework for development of …7.5
- CVE-2026-50011Netty is a network application framework for development of …7.5
Are you affected by CVE-2026-50006?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
