Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-38158: SQL Injection in ureport v2.2.9 Exposes Database Info
CVE-2026-38158
CVE-2026-38158
Summary
The /ureport/datasource/previewData component of ureport v2.2.9 has a security weakness that could allow unauthorized access to sensitive database information. This is a serious issue because it could lead to the theft of confidential data. To protect yourself, update to a fixed version of ureport or apply the recommended security patches.
Original title
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.
Original description
A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.
Vulnerability type
CWE-89
SQL Injection
Published: 16 Jul 2026 · Updated: 18 Jul 2026 · First seen: 16 Jul 2026