Unauthenticated API Vulnerability in SQL Chat by SQL Chat
CVE-2026-86123
9.4CRITICAL
What is CVE-2026-86123?
SQL Chat contains critical flaws within its API that permit unauthenticated access to database connection endpoints. These vulnerabilities allow attackers to submit custom database connection parameters and execute arbitrary SQL commands on targeted internal databases. This can lead to unauthorized data access, schema enumeration, and the ability to navigate deeper into the server's network infrastructure without any authentication process.
Affected Version(s)
sqlchat 0 <= 665af875413affadfeefff81794f1d7758782bc2
