logo

CVE-2026-38158: Critical SQL Injection in UReport v2.2.9 (CVSS 9.8)

ID: 42785d89-3f21-5e14-bf7c-b02a03fd9ab6

STIX ID: report--42785d89-3f21-5e14-bf7c-b02a03fd9ab6

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

...
...

A critical unauthenticated SQL injection (CVE-2026-38158, CVSS 9.8) affects UReport v2.2.9 and prior via the /ureport/datasource/previewData endpoint, allowing remote attackers to execute crafted SQL, exfiltrate sensitive data, bypass authentication, and potentially escalate privileges; the report includes attack examples, detection rules/log queries, and mitigation advice (restrict network access, enforce authentication, monitor logs, and block the datasource path at WAF/reverse proxy until a patch is available).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.