SQL Query Engine Vulnerability in Anyquery Exposes Sensitive Data
CVE-2026-54628

8.6HIGH

Key Information:

Vendor

Julien040

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-54628?

The Anyquery server, prior to version 0.4.5, contains a vulnerability that allows remote attackers to access sensitive internal data through unauthenticated MySQL-compatible server ports. By leveraging exposed SQLite virtual table modules, such as json_reader and log_reader, a malicious actor can exploit the server to fetch arbitrary resources from private networks or internal APIs. This can facilitate network probing and result in the disclosure of sensitive information, including cloud credentials. The issue has been addressed in version 0.4.5.

Affected Version(s)

anyquery < 0.4.5

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.