CVE Watchtower


← Back to CVE List

CVE-2026-33615NVD

Vulnerability Summary

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.
Severity Level
CRITICAL(9.1)
Published Date
Apr 2, 2026
Last Modified
Apr 16, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.11%Probability
Root Weakness (CWE)
Improper neutralization of special elements used in an SQL command, allowing attackers to modify queries.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityHigh
AvailabilityHigh