SQL Injection Vulnerability in Mahonelau Kykms Affected by Remote Exploitation
CVE-2026-102491
Key Information:
Badges
What is CVE-2026-102491?
A security flaw exists in Mahonelau Kykms, specifically within the 'doMultiFieldsOrder' function in the QueryGenerator.java file of the SqlInjectionUtil component. An attacker can exploit this vulnerability by manipulating the 'column' argument, potentially allowing for SQL injection attacks. As this exploit is publicly available, remote attackers could leverage it to execute unauthorized SQL commands on the database. The vendor has not responded to disclosure requests, leaving users vulnerable to potential risks. Given that Mahonelau Kykms follows a rolling release model, specific version information for patches is not provided, emphasizing the need for immediate attention from users.
Affected Version(s)
kykms 8f130c2d85842d5b44caae78cc46d65e505949f7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
