Stored SQL Injection Vulnerability in OpenMeter by OpenMeterio
CVE-2026-18801

9.3CRITICAL

Key Information:

Vendor

Openmeter

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-18801?

OpenMeter by OpenMeterio has a stored SQL injection vulnerability that allows attackers to manipulate usage-attribution values. By controlling customer data, an attacker can insert malicious inputs into the system. This occurs when the application uses string concatenation to handle user-provided values in SQL statements. Consequently, upon execution of metering operations, the harmful data may be processed, leading to unauthorized access to sensitive data and manipulation of database queries.

Affected Version(s)

openmeter Linux v1.0.0-beta.218

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.