CVE-2026-75132
nicheAuthenticated SQL Injection in WAPT Server 2.6.1.17834 and earlier
WAPT Server versions 2.6.1.17834 and earlier contain an SQL injection flaw (CWE-89) in the `columns` parameter of the GET /api/v3/hosts endpoint. A remote attacker holding any authenticated account with only read privileges can supply crafted values that are embedded into a PostgreSQL query built by WAPT, enabling injection of arbitrary expressions and additional SQL statements. Successful exploitation lets the attacker bypass the host-scope restrictions applied to their account and read information from other rows or tables in the backend database, with a high confidentiality impact and no direct integrity or availability impact per the 7.1 (High) CVSS 4.0 score. Any organization running an affected WAPT Server version is affected, especially where the API is reachable by low-privilege accounts. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Upgrade WAPT Server to a release newer than 2.6.1.17834 per the vendor's advisory (no fixed version is stated in the available data). In the meantime, restrict access to the /api/v3/hosts endpoint for low-privilege and read-only accounts, limit API exposure to trusted networks, and review PostgreSQL logs for unexpected queries originating from the hosts endpoint. No public exploit is known, so immediate risk is low, but the High severity and confidentiality impact make prompt patching advisable.
| Tranquil IT WAPT Server | 2.6.1.17834 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection vulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint. A remote authenticated user with read-only privileges can inject arbitrary PostgreSQL expressions into the SQL query constructed by WAPT. By exploiting the injection point, an attacker can inject additional PostgreSQL statements, bypass the host scope restrictions applied to the account, and read information from other rows or tables within the database.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.