← Back to search

CVE-2026-88402

9.8 CRITICALpublic exploit available

Published 2026-09-21 · Updated 2026-09-22

AI risk analysis

Summary
A SQL injection vulnerability in nocobase v2.1.21 enables attackers to access sensitive database information by injecting malicious SQL statements, posing a critical risk.
Exploitability
Exploitation is relatively straightforward given the vulnerability, requiring attackers to inject crafted SQL statements via specific input fields.
Blast radius
If exploited, attackers could gain full access to the database, leading to data breaches and potential loss of sensitive information.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to nocobase v2.1.22 or later.
sql-injectiondatabaseweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.