🔐 CVE Alert

CVE-2026-8462

UNKNOWN 0.0

OpenMeter SQL Injection in ClickHouse-backed Meter Definitions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.

CWE CWE-89
Vendor openmeter
Product openmeter
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for openmeter openmeter

Be the first to know when new unknown vulnerabilities affecting openmeter openmeter are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

openmeter / openmeter
1.0.0 < 1.0.0-beta.228

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/openmeterio/openmeter/pull/4383