Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-82028: Magistrala before 1.0.0 lets logged‑in users run any SQL
CVE-2026-82028 · published 13 days ago
Summary
The Magistrala platform version earlier than 1.0.0 allows a user who has signed up for an account to place a specially crafted value in a request parameter, which then gets executed as database code with full privileges. This can let the attacker read data from other customers, steal password hashes, access or modify files, and even run code on the server. Upgrade to version 1.0.0 or later, or apply the vendor’s patch, and restrict database privileges for the service accounts.
What to do
- Update absmach magistrala to version 1.0.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| absmach | magistrala | < 1.0.0 |
Original advisory text
Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or identifier quoting. Attackers with a self-registered account can substitute arbitrary subqueries to achieve cross-tenant database reads, extract pg_shadow password hashes, read and write arbitrary files, and execute arbitrary code as the postgres OS user by loading attacker-supplied shared objects, with all injected SQL executing at superuser privilege due to the default PostgreSQL role configuration.
References
- https://github.com/absmach/magistrala/pull/3581 Patch
- https://github.com/absmach/magistrala/releases/tag/v1.0.0 Vendor Advisory
- https://github.com/absmach/magistrala/pull/3581/changes/aac9461aa561c3de7aa9a0dc... Patch
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82028... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-82028 Vendor Advisory
- https://www.vulncheck.com/advisories/magistrala-sql-injection-via-format-paramet... Vendor Advisory
- https://github.com/absmach/magistrala Product
Severity
9.4
Critical
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published14 Sep 2026
Updated27 Sep 2026
First seen14 Sep 2026
Track software like this
Free during beta