HIGH🇵🇱 Wersja polska

CVE-2026-42096

CVSS 8.7v4.0pub. 2026-05-19upd. 2026-06-02

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sparxsystems Pro Cloud Server

    APP
    Sparxsystems
    ≤ 6.1.167
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-42097CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server — SQL injection bez uwierzytelnienia przez pominięcie parametru

CVE-2025-15623CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server: ujawnienie hasła do bazy danych w plaintext

CVE-2025-15624CRITICAL9.3PL ✓same product

Plaintext Storage haseł w Sparx Pro Cloud Server z OpenID

CVE-2025-15625CRITICAL9.5PL ✓same product

SQL Injection w Sparx Pro Cloud Server — nieautoryzowany dostęp do bazy danych

CVE-2026-42099HIGH7.7same product

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...