Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)
ID: 9a7d24b9-2a4f-5dd2-acce-ca7e673c3ffd
STIX ID: report--9a7d24b9-2a4f-5dd2-acce-ca7e673c3ffd
Feed Name: ThreatCluster
Threat Score
CVE-2026-52887 is a critical (CVSS 10) SQL injection vulnerability in NocoBase that allows unauthenticated remote attackers to run arbitrary SQL queries via the latestMsgReceiveTimestamp parameter of the /api/myInAppChannels endpoint. The report advises immediate upgrade to NocoBase 2.0.61 or later and implementation of input validation and parameterized queries; no public proof-of-concept or active exploitation has been observed as of publication (15 July 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
