ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability

mediumVulnerabilityimportance 45CVE-2026-92207
AI summary · glm-5.3-flash

ZDI disclosed an unpatched code injection RCE (CVE-2026-92207, CVSS 8.8) in MindsDB's OpenBBtable feature, exploitable by authenticated remote users.

ZDI-26-708 describes a code injection remote code execution vulnerability in MindsDB's OpenBBtable functionality. A remote attacker with valid authentication can execute arbitrary code on affected installations. The flaw is rated CVSS 8.8, tracked as CVE-2026-92207, and published as a 0day advisory without a referenced vendor patch.

  • Unpatched code injection RCE in MindsDB
  • Requires authentication for exploitation
  • Assigned CVE-2026-92207 with CVSS 8.8
  • Published as ZDI 0day advisory

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-92207

NVD description · AI analysis pending
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.

This source does not provide full text. Read it at zerodayinitiative.com.