What is CVE-2026-48528?
A critical unauthenticated SQL injection vulnerability has been discovered in the Metacat data repository software. This flaw affects versions 2.0.0 through 3.4.0 and is caused by unsanitized user input in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints. Immediate update to the latest Metacat version is strongly recommended.
Azərbaycanca: Metacat məlumat repozitoriyası proqramında kritik autentifikasiyasız SQL injection zəifliyi aşkar edilib. `/cn/v1/object` və `/cn/v2/object` REST API endpoint-lərinə göndərilən təmizlənməmiş istifadəçi girişi səbəbindən yaranan bu boşluq 2.0.0 ilə 3.4.0 arası versiyalara təsir edir. Metacat proqramını dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the Metacat software are vulnerable to CVE-2026-48528 SQL injection?
This vulnerability affects versions 2.0.0 through 3.4.0 of the Metacat software.
In which REST API endpoints was the CVE-2026-48528 vulnerability discovered?
The vulnerability was discovered in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.