SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-52630

CRITICAL · CVSS 9.8 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A SQL Injection vulnerability exists in Woltlab WCF versions 6.2.4 and earlier, enabling remote attackers to manipulate user options through the `updateUserOptions` function in `UserEditor.class.php` and the `update` action in `UserAction.class.php`. This flaw could lead to unauthorized data modification or access, posing a significant risk to user data integrity. Organizations using affected versions should prioritize remediation to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52630
Severity
CRITICAL
CVSS
9.8
EPSS
0.47%

Original NVD Description

SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php