Cross-Tenant Database Access Vulnerability in Coze Studio by Coze
CVE-2026-92788

8.7HIGH

Key Information:

Vendor

Coze-dev

Vendor
CVE Published:
16 September 2026

What is CVE-2026-92788?

Coze Studio versions up to 0.5.1 have a vulnerability allowing authenticated users to exploit SQL customization nodes in workflows. This flaw occurs due to insufficient validation of table names, permitting attackers to manipulate SQL statements against databases not belonging to their workspace. As a result, attackers can enumerate and access predictable table identifiers, exposing sensitive data or altering database contents.

Affected Version(s)

coze-studio 0 <= 0.5.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.