SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-76848

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

TypeORM's SelectQueryBuilder.distinctOn method is vulnerable due to inadequate validation of user-supplied input, allowing attackers to inject arbitrary SQL expressions into the generated query. This can lead to unauthorized data access through SQL injection, enabling attackers to infer sensitive information from the database. Organizations using TypeORM with PostgreSQL should prioritize addressing this vulnerability to protect their data integrity and confidentiality.

CVE
CVE-2026-76848
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.