Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-38158: SQL Injection in ureport v2.2.9 Exposes Database Info

CVE-2026-38158 CVE-2026-38158
Summary

The /ureport/datasource/previewData component of ureport v2.2.9 has a security weakness that could allow unauthorized access to sensitive database information. This is a serious issue because it could lead to the theft of confidential data. To protect yourself, update to a fixed version of ureport or apply the recommended security patches.

Original title
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.
Original description
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.
Vulnerability type
CWE-89 SQL Injection
Published: 16 Jul 2026 · Updated: 18 Jul 2026 · First seen: 16 Jul 2026