CVE-2026-8462
OpenMeter SQL Injection in ClickHouse-backed Meter Definitions
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
| CWE | CWE-89 |
| Vendor | openmeter |
| Product | openmeter |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for openmeter openmeter
Be the first to know when new unknown vulnerabilities affecting openmeter openmeter are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
openmeter / openmeter
1.0.0 < 1.0.0-beta.228