SQL Injection Vulnerability in R2R by SciPhi-AI
CVE-2026-82526
Key Information:
Badges
What is CVE-2026-82526?
The R2R product by SciPhi-AI up to version 3.6.6 harbors a significant vulnerability that allows an unauthenticated attacker to exploit a stacked SQL injection weakness. This vulnerability is triggered by manipulating the index name parameter during the index creation process. The absence of proper identifier quoting or allowlist validation enables attackers to interpolate the index name directly into a CREATE INDEX statement, leading to unauthorized execution of arbitrary SQL statements, including both Data Definition Language (DDL) and Data Manipulation Language (DML) commands, under a PostgreSQL superuser account.
Affected Version(s)
R2R 0 <= 3.6.6
R2R 0 <= 9c5a94d151f90876bd7eb860f300a8fd662dc481
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
