{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ar2rr2r/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:r2r:r2r:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82526"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["R2R (\u003c= 3.6.6)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["R2R"],"content_html":"\u003cp\u003eR2R versions through 3.6.6 contain a high-severity stacked SQL injection vulnerability (CVE-2026-82526). The flaw resides in the vector index creation endpoint, where the 'index name' parameter is interpolated directly into a 'CREATE INDEX' statement. Due to a lack of identifier quoting and input validation, an unauthenticated attacker can inject arbitrary SQL commands. Because the application interacts with the backend database using a PostgreSQL superuser account, successful exploitation allows for unauthorized DDL and DML operations. This poses a significant risk to the integrity and confidentiality of the underlying database. Defenders should prioritize patching affected R2R instances to version 3.6.7 or later if available, or restrict access to the index creation API.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits full database compromise. Attackers can execute arbitrary SQL statements, potentially leading to data exfiltration, modification of system configurations, or administrative access to the underlying PostgreSQL instance. As this is an unauthenticated vector, it is accessible to any remote actor capable of reaching the R2R API.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch R2R instances to a version higher than 3.6.6 immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on the index name parameter to ensure it conforms to expected identifier patterns (e.g., alphanumeric only).\u003c/li\u003e\n\u003cli\u003eReview database logs for unexpected DDL statements or queries originating from the R2R service account.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the R2R vector index creation API to authorized clients only via firewall or proxy rules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T19:22:21Z","date_published":"2026-09-03T19:22:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-r2r-sql-injection/","summary":"R2R versions through 3.6.6 contain a stacked SQL injection vulnerability allowing unauthenticated attackers to execute arbitrary DDL and DML commands via the index name parameter.","title":"Unauthenticated Stacked SQL Injection in R2R","url":"https://feed.craftedsignal.io/briefs/2026-09-r2r-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:r2r:r2r:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}