Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-67689: FineAdmin V1.0: Arbitrary Code Execution via Paginated List Endpoints

CVE-2026-67689 CVE-2026-67689
Summary

The FineAdmin V1.0 software has a security weakness that allows a remote attacker to execute malicious code. This is a concern because an attacker could potentially gain unauthorized access to sensitive data or disrupt the system. To mitigate this risk, update FineAdmin V1.0 to a newer version or patch the vulnerability as soon as possible.

Original title
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
Original description
SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints
Vulnerability type
CWE-89 SQL Injection
Published: 6 Aug 2026 · Updated: 7 Aug 2026 · First seen: 6 Aug 2026