Unauthenticated SQL Injection Vulnerability in Metacat Data Repository Software
CVE-2026-48528
9.8CRITICAL
What is CVE-2026-48528?
Metacat, a crucial data repository software, is vulnerable due to unauthenticated SQL injection paths in its REST API endpoints. Exploiting this vulnerability allows attackers to manipulate the 'nodeId' parameter, leading to the execution of arbitrary SQL commands on the associated PostgreSQL database. This can result in unauthorized data access, inclusion of sensitive information in error responses, and even data alterations without needing to authenticate. Metacat versions 2.0.0 to 3.4.0 are affected, posing significant risks for organizations utilizing this software in the DataONE network. Users are recommended to upgrade to version 3.4.1 or mitigate risk by disabling the vulnerable /cn endpoints.
Affected Version(s)
metacat >= 2.0.0, < 3.4.1
