What is CVE-2026-72565?
CVE-2026-72565 is an SQL injection vulnerability in Tencent APIJSON through version 8.1.8 that allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables using the @having operator. Immediate upgrading to a patched version is strongly recommended to mitigate potential data breaches.
Azərbaycanca: CVE-2026-72565, Tencent-in APIJSON 8.1.8-ə qədər versiyalarında autentifikasiya olunmamış uzaqdan hücumçulara cədvəl üzrə giriş nəzarətini keçərək ixtiyari verilənlər bazası cədvəllərini oxumağa imkan verən SQL injection zəifliyidir. Bu, @having operatoru vasitəsilə həyata keçirilir. Dərhal APIJSON versiyasını ən son təhlükəsizlik yamaları ilə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which product is affected by CVE-2026-72565?
CVE-2026-72565 affects Tencent's APIJSON through version 8.1.8.
How can attackers exploit CVE-2026-72565?
Unauthenticated attackers can use SQL injection via the @having operator to bypass per-table access control and read arbitrary database tables.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.