SQL Injection Vulnerability in JetBrains Exposed Products
CVE-2026-108474

9.8CRITICAL

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108474?

JetBrains Exposed prior to version 1.5.1 is susceptible to SQL injection attacks due to unescaped string arguments used in several SQL functions. This vulnerability can allow unauthorized users to manipulate database queries, potentially leading to exposure of sensitive information or data corruption. Users are advised to update to the latest version to mitigate this risk and strengthen their database security.

Affected Version(s)

Exposed 0 < 1.5.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.