
💉 New SQL injection discovered in OPMS CVE-2026-19354 affects the OPMS project. The vulnerability is located in message.go, where manipulation of an ids value used in an SQL IN clause can result in SQL injection. 📅 Disclosed: August 8. 🔎 Source: CVE/Vulnerability feed via YANAC. #SQLInjection #CVE #AppSec #CyberSecurity
Post summary
The post announces the discovery of CVE‑2026‑19354, detailing a SQL injection flaw in OPMS, but does not provide a PoC, exploit, patch, or evidence of active exploitation.
