Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sciphi-ai
Sciphi-ai r2r |
|
| Vendors & Products |
Sciphi-ai
Sciphi-ai r2r |
Thu, 03 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account. | |
| Title | R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T13:41:55.370Z
Reserved: 2026-08-29T17:20:57.082Z
Link: CVE-2026-82526
Updated: 2026-09-04T12:28:54.994Z
Status : Received
Published: 2026-09-03T19:17:29.950
Modified: 2026-09-04T14:17:20.257
Link: CVE-2026-82526
No data.
OpenCVE Enrichment
Updated: 2026-09-03T20:15:06Z