CVE-2026-86123 UNKNOWN

CVE-2026-86123

Published: 2026-09-05

Description

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…