CVE-2026-91198
Last modified
CVE-2026-91198 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| growthbook | growthbook | <= 5.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-91198?
How severe is CVE-2026-91198?
How do I fix CVE-2026-91198?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9116Insufficient policy enforcement in ServiceWorker in Google C…4.3
- CVE-2026-9117Type Confusion in GFX in Google Chrome on Linux, ChromeOS pr…7.5
- CVE-2026-9118Use after free in XR in Google Chrome on Windows prior to 14…8.8
- CVE-2026-91181Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7…6.5
- CVE-2026-9119Heap buffer overflow in WebRTC in Google Chrome on prior to …8.8
- CVE-2026-91197Flowable flowable-engine through 8.0.0 contains an XML exter…6.5
- CVE-2026-91199Refly through 1.1.0 contains a server-side request forgery v…5
- CVE-2026-9120Use after free in WebRTC in Google Chrome prior to 148.0.777…8.8
- CVE-2026-91200DevSpace through 6.3.21 fails to reject parent-directory seg…8.8
- CVE-2026-91201DocsGPT through 0.20.0 posts OAuth connector session tokens …5.4
- CVE-2026-9121Out of bounds read in GPU in Google Chrome on prior to 148.0…8.8
- CVE-2026-9122Out of bounds read in GPU in Google Chrome on Mac prior to 1…6.5
Are you affected by CVE-2026-91198?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
