SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57230

MEDIUM · CVSS 5.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

OpenReplay's session search and analytics API in enterprise editions with multi-tenancy enabled is vulnerable due to improper handling of user input in ClickHouse queries, allowing authenticated users to access any ClickHouse table through crafted queries. This could lead to unauthorized data exposure and disruption of session searches for all users until the compromised key is removed. Organizations using affected versions should prioritize upgrading to version 1.27.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57230
Severity
MEDIUM
CVSS
5.4
EPSS
0.21%

Original NVD Description

OpenReplay is a self-hosted session replay suite. Prior to 1.27.0, the session search and analytics API in enterprise editions with multi-tenancy enabled built ClickHouse queries by inserting user input into the query string, including two positions that took input without escaping, allowing an authenticated member to read any ClickHouse table through blind boolean and time-based exfiltration and to break the project's session search for all viewers until the stored key is removed. This issue is fixed in version 1.27.0.