Cross-Tenant Database Access Vulnerability in Coze Studio by Coze
CVE-2026-92788
8.7HIGH
What is CVE-2026-92788?
Coze Studio versions up to 0.5.1 have a vulnerability allowing authenticated users to exploit SQL customization nodes in workflows. This flaw occurs due to insufficient validation of table names, permitting attackers to manipulate SQL statements against databases not belonging to their workspace. As a result, attackers can enumerate and access predictable table identifiers, exposing sensitive data or altering database contents.
Affected Version(s)
coze-studio 0 <= 0.5.1
