๐Ÿ” CVE Alert

CVE-2026-48114

CRITICAL 9.8

Metacat has an unauthenticated SQL injection vulnerability

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistration.dbInsert() builds an INSERT against HARVEST_SITE_SCHEDULE via string concatenation, using a quoteString() helper that performs raw single-quote wrapping without escaping. Three request parameters reach the sink: unit, contactEmail, and documentListURL. The servlet does not verify a real LDAP identity. Allowing the vulnerable insert to proceed. Since the PostgreSQL backend permits stacked queries via Statement.executeUpdate(), this vulnerability allows full read/write/execute access in the Metacat database context. The vulnerability was remediated in Metacat 3.0.0.

CWE CWE-89 CWE-287
Vendor nceas
Product metacat
Published Jun 15, 2026
Stay Ahead of the Next One

Get instant alerts for nceas metacat

Be the first to know when new critical vulnerabilities affecting nceas metacat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

NCEAS / metacat
>= 2.0.0, < 3.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NCEAS/metacat/security/advisories/GHSA-wrc6-rc34-hrcg github.com: https://github.com/NCEAS/metacat/commit/820d595309b399fdbdf4983bd1b1dd795773472a