CVE 8.8 HIGH

CVE-2026-31069_CVE-2026-31069

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands.

AI Analysis

SQL Injection vulnerability in the EventRepository

Basic Information

ID CVE-2026-31069
Source mitre
Published May 19, 2026 at 00:00
Modified May 20, 2026 at 13:50

Affected Product

Vendor BillaBear
Product BillaBear
Version all versions prior to Jan 2026
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor BillaBear
Product BillaBear
Version all versions prior to Jan 2026

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.