CVE-2026-6093 Details
Description
Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8.
A SQL injection vulnerability has been identified in Corteza version 2024.9.8, specifically within its Microsoft SQL Server (MSSQL) backend. The issue arises when filtering Compose records by the 'meta' field. The vulnerability is rooted in improper string escaping of single quotes in T-SQL, allowing injection into SQL queries. This exploitation can be carried out by any authenticated user with 'records.search' permission on a module that includes a 'meta' attribute.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://fluidattacks.com/es/advisories/motley | CISA-ADP | AdvisoryExploitRemedy |
| https://fluidattacks.com/es/advisories/motley | [email protected] | AdvisoryExploitRemedy |
| https://github.com/cortezaproject/corteza | [email protected] | ProductSource CodeVendor |
| https://github.com/cortezaproject/corteza/commit/64b58b9d7324e77248bacd183fb994ff338091ec | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Corteza | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | [email protected] |
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion