CVE-2026-79536 Details
Description
bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.
A SQL injection vulnerability has been identified in Bytebase DBHub version 1.2.0 and earlier, within the SQL parser component. This vulnerability allows attackers to bypass the application's read-only mode on MySQL and MariaDB databases, enabling them to execute write operations or destructive data definition language commands, such as dropping tables. The issue arises because the SQL classifier used to enforce read-only mode fails to recognize certain comment syntax, allowing malicious SQL statements to be crafted and executed.
To address this vulnerability, disable `multipleStatements` on the database connection to prevent stacked statements from executing based on the classifier's assessment. Additionally, enforce read-only access at the database level using a read-only transaction or a least-privilege database account, and update the SQL classifier to properly parse `#` comments in accordance with the target SQL dialect's default mode.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.traceforce.ai/security-advisories/cve-2026-79536 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| bytebase DBHub | <v1.2.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion