๐Ÿ” CVE Alert

CVE-2026-63080

MEDIUM 6.5

Aptabase SQL Injection via ClickHouse query backend

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants by injecting unsanitized filter parameters into Liquid SQL templates. Attackers can supply malicious values through EventName, CountryCode, OsName, DeviceModel, AppVersion, or SessionId parameters to inject a UNION ALL statement that bypasses the app_id tenant isolation filter across thirteen of the fifteen stats API endpoints.

CWE CWE-89
Vendor aptabase
Product aptabase
Published Jul 21, 2026
Stay Ahead of the Next One

Get instant alerts for aptabase aptabase

Be the first to know when new medium vulnerabilities affecting aptabase aptabase are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

aptabase / aptabase
0 โ‰ค 5a8936852a20c26267ffaefd3544f91e3ca94135

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
yoyochaud.fr: https://yoyochaud.fr/en/chaud/cve-2026-63080-aptabase-sql-injection/ vulncheck.com: https://www.vulncheck.com/advisories/aptabase-sql-injection-via-clickhouse-query-backend

Credits

YoyoChaud