SQL Injection Vulnerability in WAPT Server by WAPT
CVE-2026-75132

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-75132?

WAPT Server versions 2.6.1.17834 and below are vulnerable to an SQL injection flaw through the columns parameter of the GET /api/v3/hosts endpoint. This issue allows a remote authenticated user with read-only privileges to inject arbitrary PostgreSQL expressions into the constructed SQL query. By exploiting this vulnerability, attackers can potentially execute additional PostgreSQL statements, bypass account restrictions, and gain unauthorized access to other database rows or tables, leading to a compromise of sensitive information.

Affected Version(s)

WAPT 2.6.x <= 2.6.1.17834

WAPT 2.6.x <= 2.6.1.17834

WAPT 2.6.1.17852

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Elymaro (Aurélien Bourdois)
.