logo

Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)

ID: ba8e7eac-e167-54c1-bc30-c8eb88664247

STIX ID: report--ba8e7eac-e167-54c1-bc30-c8eb88664247

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

...
...

CVE-2026-52887 is a critical SQL injection in NocoBase allowing unauthenticated remote execution of arbitrary SQL via the /api/myInAppChannels latestMsgReceiveTimestamp parameter (CVSS 10). Users are advised to upgrade to NocoBase 2.0.61 or later and apply input validation/parameterized queries; no public PoC or active exploitation has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.