What is CVE-2026-63080?
Aptabase through a specific commit contains a SQL injection vulnerability in the ClickHouse query backend. It allows authenticated attackers to read event data across all tenants by injecting unsanitized filter parameters into Liquid SQL templates. Immediate update to the latest version and strengthening input validation is recommended.
Azərbaycanca: Aptabase proqramının müəyyən bir versiyasında ClickHouse sorğu sistemində SQL injection zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş hücumçulara filter parametrləri vasitəsilə bütün təşkilatların hadisə məlumatlarını oxumağa imkan verir. Dərhal proqramı ən son versiyaya yeniləmək və giriş yoxlamalarını gücləndirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What does the CVE-2026-63080 vulnerability in Aptabase allow?
The CVE-2026-63080 vulnerability allows authenticated attackers to read event data across all tenants via filter parameters.
What measures should be taken to mitigate CVE-2026-63080?
Immediate update to the latest version and strengthening input validation is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.