CVE-2026-108474

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-10: 210-10
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR

    🚨Critical - JetBrains Exposed SQL Injection via Unescaped SQL Function Args (CVE-2026-108474) JetBrains Exposed < 1.5.1 allows SQLi where several SQL functions accept raw string arguments that aren’t escaped/parameterized. Crafted input passed into these function parameters can break out of the query context and execute attacker-controlled SQL, enabling data exfiltration/modification. Queries using bound parameters aren’t impacted. 👉Affected: JetBrains Exposed < 1.5.1 | Upgrade to 1.5.1

    0000026
    315 followersView on X
  • VulDB 🛡@vuldb

    🚨 Attention, elevated activities detected targeting JetBrains Exposed (CVE-2026-108474) vuldb.​com/vuln/416028/cti https://t.co/UkqVbaMyWU

    0000068
    2.3K followersView on X

Explore more