SQL Injection Vulnerability in WAPT Server by WAPT
CVE-2026-75132
7.1HIGH
What is CVE-2026-75132?
WAPT Server versions 2.6.1.17834 and below are vulnerable to an SQL injection flaw through the columns parameter of the GET /api/v3/hosts endpoint. This issue allows a remote authenticated user with read-only privileges to inject arbitrary PostgreSQL expressions into the constructed SQL query. By exploiting this vulnerability, attackers can potentially execute additional PostgreSQL statements, bypass account restrictions, and gain unauthorized access to other database rows or tables, leading to a compromise of sensitive information.
Affected Version(s)
WAPT 2.6.x <= 2.6.1.17834
WAPT 2.6.x <= 2.6.1.17834
WAPT 2.6.1.17852
