CVE-2026-62238
Last modified
CVE-2026-62238 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating asset display names into raw SQL. An authenticated attacker with asset creation or rename permissions can inject SQL through the asset name parameter and receive query results in the exported CSV response, enabling database data exfiltration.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openremote | Openremote | < 1.26.0 |
References
- https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7vExploit, Mitigation, Vendor Advisory
- https://github.com/openremote/openremote/security/advisories/GHSA-cgfv-jrfp-2r7vExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-62238?
How severe is CVE-2026-62238?
How do I fix CVE-2026-62238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62232Grav before 2.0.4 contains a two-factor authentication bypas…9.1
- CVE-2026-62233grav-plugin-api before 1.0.6 fails to validate super-admin s…8.8
- CVE-2026-62234Grav before 2.0.4 fails to restrict cURL protocols in webhoo…8.4
- CVE-2026-62235Grav Flex-Objects before version 1.4.3 contains a broken acc…6.3
- CVE-2026-62236grav-plugin-login before 3.8.11 contains a cross-site reques…5.4
- CVE-2026-62237Grav before 2.0.4 contains a regular expression denial of se…6.5
- CVE-2026-62239FlashAttention through 2.8.3.post1, fixed in commit 0816ef1,…6.6
- CVE-2026-6224A security flaw has been discovered in nocobase plugin-workf…7.3
- CVE-2026-62240CrewAI before 1.15.1 contains a server-side request forgery …8.3
- CVE-2026-62241clawvet self-hosted API server (apps/api) before 0.7.5 hard-…9.3
- CVE-2026-62242Spring Boot Admin Server before 4.1.2 contains a server-side…8.6
- CVE-2026-62246Kamaji is the Hosted Control Plane Manager for Kubernetes. P…8.5
Are you affected by CVE-2026-62238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
