{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asql_chatsql_chat/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sql_chat:sql_chat:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-86123"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SQL Chat"],"_cs_severities":["high"],"_cs_tags":["cve-2026-86123","sql-injection","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["SQL Chat"],"content_html":"\u003cp\u003eSQL Chat contains four unauthenticated API endpoints that fail to sanitize client-supplied database connection parameters. This vulnerability, tracked as CVE-2026-86123, allows remote, unauthenticated attackers to force the application to establish connections to arbitrary external or internal database hosts. Once connected, an attacker can execute arbitrary SQL queries, enumerate database schemas, and potentially exfiltrate sensitive data. Furthermore, because these connections originate from the SQL Chat server itself, the vulnerability provides an attacker with a foothold to pivot into internal network segments that may not be directly reachable from the internet. This issue is critical for organizations deploying SQL Chat in environments with access to sensitive internal database resources, as it bypasses standard authentication and access controls for the database layer.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to data confidentiality and network integrity. Successful exploitation enables unauthorized schema enumeration and data exfiltration from any database the SQL Chat server can reach. In segmented networks, the service can be leveraged to bypass perimeter firewalls, allowing attackers to reach and interact with internal-only database instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately: Ensure SQL Chat is updated to the latest available version that contains the fix for CVE-2026-86123.\u003c/li\u003e\n\u003cli\u003eNetwork isolation: Restrict the network reachability of the SQL Chat server using host-based firewalls or VPC security groups to only those database hosts that are strictly required for its operation.\u003c/li\u003e\n\u003cli\u003eMonitoring: Monitor web access logs for unauthenticated POST requests to API endpoints responsible for database configuration or connection establishment.\u003c/li\u003e\n\u003cli\u003eDatabase auditing: Enable audit logging on database servers accessible by the SQL Chat instance to detect unauthorized queries or abnormal connection patterns.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-05T11:31:46Z","date_published":"2026-09-05T11:31:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86123/","summary":"CVE-2026-86123 allows unauthenticated attackers to supply arbitrary database connection parameters, enabling unauthorized SQL execution against internal infrastructure.","title":"Unauthenticated SQL Injection and Database Access in SQL Chat","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86123/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:sql_chat:sql_chat:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}