SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13337

MEDIUM · CVSS 5.1 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the NetBotz database that allows for SQL injection through malicious HQL queries, potentially compromising data integrity and confidentiality when a user is authenticated via the web interface. Organizations utilizing NetBotz should prioritize addressing this issue to mitigate risks associated with unauthorized data access and manipulation.

CVE
CVE-2026-13337
Severity
MEDIUM
CVSS
5.1
EPSS
0.18%

Original NVD Description

CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.