Authorization Flaw in Mercator's Query Engine Affects User Data Access
CVE-2026-49344

7.1HIGH

Key Information:

Vendor

Sourcentis

Status
Vendor
CVE Published:
19 June 2026

What is CVE-2026-49344?

Mercator, an open source web application designed for mapping information systems, has a security flaw in its Query Engine that allows any authenticated user, including those with limited read-only access, to execute queries beyond their authorized scope. Specifically, the Query Engine's endpoint (/admin/queries/execute) lacks proper authorization controls, leaving sensitive model data, such as user information, exposed. Furthermore, the password field, though intended to be protected, can inadvertently be accessed through filter predicates. Critical endpoints like schema() and schemaModel() are also affected by similar oversight, underscoring the need for security patches. Version 2025.05.19 addresses these vulnerabilities to enhance user data protection.

Affected Version(s)

mercator < 2025.05.19

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.