CVE Watchtower


← Back to CVE List

CVE-2026-33614NVD

Vulnerability Summary

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Severity Level
HIGH(7.5)
Published Date
Apr 2, 2026
Last Modified
Apr 16, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.05%Probability
Root Weakness (CWE)
Improper neutralization of special elements used in an SQL command, allowing attackers to modify queries.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone