Skip to content
Threat Feed
high threat exploited

SQL Injection Vulnerability in mahonelau kykms

A SQL injection vulnerability in the QueryGenerator.doMultiFieldsOrder function of mahonelau kykms allows remote attackers to execute arbitrary database queries via the column argument.

CVE search metadata

CVE search record: CVE-2026-102491. Severity: high. CVSS: 7.3. KEV: no. Product: kykms (up to 8f130c2d85842d5b44caae78cc46d65e505949f7). Brief: SQL Injection Vulnerability in mahonelau kykms. Brief link: https://feed.craftedsignal.io/briefs/2026-09-kykms-sql-injection/

A SQL injection vulnerability has been identified in the kykms project maintained by mahonelau, specifically affecting all versions up to commit 8f130c2d85842d5b44caae78cc46d65e505949f7. The vulnerability exists within the QueryGenerator.doMultiFieldsOrder function inside the SqlInjectionUtil.java file. An attacker can manipulate the column argument to inject malicious SQL commands, enabling unauthorized interaction with the underlying database. The vulnerability is remotely exploitable, and proof-of-concept exploit code is publicly available, increasing the risk of active exploitation. The project utilizes a rolling release model, and no specific patch version has been issued by the vendor to address this flaw. Defenders should prioritize identifying instances of this component and implementing input validation controls.

Impact

Successful exploitation allows remote attackers to execute arbitrary SQL queries against the database used by the kykms component. This can lead to unauthorized data exfiltration, modification of database contents, or potential service disruption. Given the availability of public exploit code, systems utilizing this library are at a high risk of compromise.

Recommendation

  • Perform an inventory of all applications within the environment to identify any software integrating the mahonelau kykms library.
  • Monitor web application logs for suspicious characters (e.g., single quotes, semicolons, comment operators) within the column parameter targeting endpoints that utilize the QueryGenerator functionality.
  • Implement strict input validation and parameterized queries for all database interactions to mitigate the impact of potential SQL injection vectors.
  • Since the vendor has not provided a patched version, consider implementing a Web Application Firewall (WAF) rule to inspect and block malicious payloads targeting the specific vulnerable argument.

Immediate actions

Audit applications for kykms library usage and identify affected systems

IT Operations 48h

Mitigations

Deploy WAF rules to inspect and block malicious SQL syntax in requests containing the column parameter

immediate SOC

CVE-2026-102491

Gaps

  • Lack of vendor-provided patch requires compensating controls