CVE-2026-91198 UNKNOWN

CVE-2026-91198

Published: 2026-09-14

Description

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names, filter values and datasource identifiers.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…