{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/magistrala/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:magistrala:magistrala:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-82028"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Magistrala (\u003c 1.0.0)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["Magistrala"],"content_html":"\u003cp\u003eMagistrala versions prior to 1.0.0 contain a critical SQL injection vulnerability residing within the timescale-reader and postgres-reader HTTP API services. The vulnerability stems from improper handling of the format query parameter, which is interpolated directly into the SQL FROM clause without parameterization or identifier quoting. An authenticated attacker, including those with self-registered accounts, can manipulate this parameter to inject arbitrary subqueries. Because the application connects to the underlying PostgreSQL database with superuser privileges, successful exploitation allows an attacker to perform cross-tenant data exfiltration, extract sensitive credentials such as pg_shadow hashes, read or write arbitrary files on the filesystem, and execute arbitrary system commands by loading attacker-supplied shared objects. This vulnerability represents a significant risk as it grants an authenticated user full control over the database and the underlying operating system user hosting the PostgreSQL process.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-82028 allows for complete compromise of the Magistrala application data and the hosting server environment. Attackers can gain unauthorized access to data across all tenants, steal administrative credentials, and achieve remote code execution (RCE) with the privileges of the postgres OS user, leading to a full host takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Magistrala to version 1.0.0 or later immediately to patch the vulnerable API services.\u003c/li\u003e\n\u003cli\u003eAudit database access logs for unusual SQL queries involving the timescale-reader or postgres-reader endpoints that utilize unexpected subqueries or attempts to access pg_shadow.\u003c/li\u003e\n\u003cli\u003eRestrict the privileges of the PostgreSQL service account to adhere to the principle of least privilege, preventing the application from executing commands or file operations at the OS level.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T21:35:48Z","date_published":"2026-09-14T21:35:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-magistrala-sqli/","summary":"Magistrala versions prior to 1.0.0 contain a SQL injection vulnerability in the timescale-reader and postgres-reader services allowing authenticated users to achieve remote code execution via arbitrary SQL execution.","title":"SQL Injection in Magistrala HTTP API","url":"https://feed.craftedsignal.io/briefs/2026-09-magistrala-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Magistrala","version":"https://jsonfeed.org/version/1.1"}