CVE 7.2 HIGH

Tarkov Data Manager has Authenticated SQL Injection_CVE-2026-21856

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vulnerability in the webhook edit and scanner api endpoints that allow an authenticated attacker to execute arbitrary SQL queries against the MySQL database. Commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8 contains a patch.

Basic Information

ID CVE-2026-21856
Source GitHub_M
Published Jan 7, 2026 at 18:18
Modified Jan 7, 2026 at 18:34

Affected Product

Vendor the-hideout
Product tarkov-data-manager
Version <= 2.0.0
Affected Versions the-hideout tarkov-data-manager <= 2.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.