← back
CVE-2026-49490

OpenCATS - SQL Injection in DataGrid Filter Handling for Tags Column

CVSS 8.6 HIGHEPSS 0.2%CWE-89
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.6EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
31 May 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenCATS from version 0.9.1a contains an SQL injection vulnerability in DataGrid filter handling that allows authenticated attackers to inject SQL through crafted filters targeting the non-filterable Tags column in the Candidates DataGrid. Attackers can bypass column filterable restrictions by manipulating filter requests to execute arbitrary SQL queries against the database.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
OpenCATS · OpenCATS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →