SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-52348

CRITICAL · CVSS 9.8 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A SQL injection vulnerability exists in the order() method of CrudOption.java in cool-admin-java version 8.0.0, allowing attackers to manipulate database queries and potentially gain unauthorized access to sensitive data. This critical flaw, rated 9.8 on the CVSS scale, poses a significant risk to applications utilizing this version of the Java framework. Organizations using cool-admin-java should prioritize immediate patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52348
Severity
CRITICAL
CVSS
9.8
EPSS
0.26%
Java

Original NVD Description

cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.