Unauthenticated API Vulnerability in SQL Chat by SQL Chat
CVE-2026-86123

9.4CRITICAL

Key Information:

Vendor

Sqlchat

Status
Vendor
CVE Published:
5 September 2026

What is CVE-2026-86123?

SQL Chat contains critical flaws within its API that permit unauthenticated access to database connection endpoints. These vulnerabilities allow attackers to submit custom database connection parameters and execute arbitrary SQL commands on targeted internal databases. This can lead to unauthorized data access, schema enumeration, and the ability to navigate deeper into the server's network infrastructure without any authentication process.

Affected Version(s)

sqlchat 0 <= 665af875413affadfeefff81794f1d7758782bc2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.