CVE-2026-8462
nicheUnauthenticated SQL Injection in OpenMeter meters API (before 1.0.0-beta.228)
OpenMeter before v1.0.0-beta.228 fails to safely handle user-controlled JSONPath values in meter definitions backed by ClickHouse, resulting in SQL injection (CWE-89). A remote, unauthenticated attacker can submit crafted JSONPath expressions to the meters API, causing them to be incorporated into ClickHouse queries. Successful exploitation allows the attacker to read or modify metering event data and can potentially disrupt the service, leading to denial of service. All deployments of OpenMeter earlier than v1.0.0-beta.228 on any platform are affected, with self-hosted instances of this open-source usage-metering platform being the primary exposure. No public proof-of-concept is known, the issue is not listed in CISA's KEV, and there are no confirmed reports of exploitation so far.
What to do: Upgrade OpenMeter to v1.0.0-beta.228 or later as soon as possible. If an immediate upgrade is not possible, restrict network access to the meters API (e.g., place it behind an authenticating reverse proxy or limit it to trusted networks). Afterwards, review ClickHouse logs and metering event data for signs of unauthorized access or modification.
| OpenMeter | all versions before v1.0.0-beta.228 (all platforms) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.