CRITICAL🇵🇱 Wersja polska

CVE-2026-42097

CVSS 9.3v4.0pub. 2026-05-19upd. 2026-06-02

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

🤖 AI Analysis
How it works

The application verifies user identity based on the 'model' parameter contained in the request URL. An attacker can omit this parameter in the URL and instead place the model name solely in the binary content (blob) of the POST request body. The authentication mechanism does not properly analyze this alternative path, as a result the SQL query reaches the database without prior verification of the requester's identity. This is a vulnerability classified as CWE-639 (Authorization Bypass Through User-Controlled Key) with a SQL injection component.

Impact

An unauthenticated remote attacker can execute arbitrary SQL queries in the server's database, which may lead to unauthorized reading and modification of stored data, including potentially sensitive architectural modeling data.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Since the manufacturer did not respond to the vulnerability report, it is recommended to restrict network access to Sparx Pro Cloud Server instances (e.g., through firewall or VPN) and monitor HTTP traffic for suspicious POST requests until an official patch is released.

Who is affected

Sparx Pro Cloud Server version 6.1 (build 167) and lower — confirmed vulnerable. Other versions were not tested and may also be vulnerable. The manufacturer did not provide information about the scope of vulnerable versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sparxsystems Pro Cloud Server

    APP
    Sparxsystems
    ≤ 6.1.167
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2025-15623CRITICAL9.3PL ✓same product

Sparx Pro Cloud Server: ujawnienie hasła do bazy danych w plaintext

CVE-2025-15624CRITICAL9.3PL ✓same product

Plaintext Storage haseł w Sparx Pro Cloud Server z OpenID

CVE-2025-15625CRITICAL9.5PL ✓same product

SQL Injection w Sparx Pro Cloud Server — nieautoryzowany dostęp do bazy danych

CVE-2026-42096HIGH8.7same product

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to l...

CVE-2026-42099HIGH7.7same product

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. T...