What is CVE-2026-18801?
A stored SQL injection vulnerability was discovered in OpenMeter's handling of customer usage-attribution values. An attacker can inject malicious code via `usageAttribution.key` or `usageAttribution.subjectKeys` fields, leading to unauthorized database access. OpenMeter users should immediately apply the security patch provided by the vendor.
Azərbaycanca: OpenMeter platformasında stored SQL injection zəifliyi aşkarlanıb. Zərərli şəxs müştəri məlumatlarındakı `usageAttribution` sahələrinə təhlükəli kod yerləşdirərək verilənlər bazasına icazəsiz giriş əldə edə bilər. OpenMeter istifadəçiləri təcili olaraq təchizatçı tərəfindən təqdim edilən təhlükəsizlik yamasını tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which fields must an attacker target to exploit the stored SQL injection vulnerability discovered in OpenMeter?
An attacker must inject malicious code into the `usageAttribution.key` or `usageAttribution.subjectKeys` fields.
What action should OpenMeter users take against the CVE-2026-18801 vulnerability?
Users should immediately apply the security patch provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.