CVE-2026-30860Disclosure(tencent / weknora)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch tencent weknora systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect child nodes within PostgreSQL array expressions and row expressions, allowing attackers to bypass SQL injection protections. By smuggling dangerous PostgreSQL functions inside these expressions and chaining them with large object operations and library loading capabilities, an unauthenticated attacker can achieve arbitrary code execution on the database server with database user privileges. This issue has been patched in version 0.2.12.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • weknora

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-07); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
weknora

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-07: 4Mentions · 2026-03-08: 2Mentions · 2026-03-12: 1Mentions · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-08: 1Exploit Tool / Code · 2026-03-08: 1Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-07: 4Technical Details · 2026-03-08: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-23: 103-0703-0803-1203-23
Signal classification2 categories
Disclosure
675.0%
Patch
225.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-074
Disclosure3Patch1
2026-03-082
Disclosure2
2026-03-121
Disclosure1
2026-03-231
Patch1
Full discourse8 posts
  • maru@maru1151157
    Disclosure

    🚨 CVE-2026-30860 (CVSS: 9.9) WeKnora 0.2.12 以前では、PostgreSQL配列/行式でRCE可能。SQLインジェクション防御をバイパスし、任意コード実行可能。対策: 0.2.12 へのアップデート。 https://maruomosquit.com/vulnerability/CVE-2026-30860/ #脆弱性 #セキュリティ

    Post summary

    CVE‑2026‑30860 exposes a remote code execution flaw via PostgreSQL array/row expressions in WeKnora versions before 0.2.12, bypassing SQL injection defenses; upgrading to 0.2.12 mitigates the issue.

    010170439
    1.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30860 Remote Code Execution in WeKnora Before 0.2.12 via PostgreSQL Arr... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30860 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-30860 as a remote code execution flaw in WeKnora before v0.2.12, linking to a Vulmon details page but providing no PoC, exploit code, or patch information.

    0001046
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical RCE vulnerability via SQL injection bypass affects `WeKnora` AI Database Query Tool (CVE-2026-30860). Assess exposure and apply vendor patches. #infosec #RCE #SQLi https://www.pulsepatch.io/posts/cve-2026-30860-weknora-rce-sqli-bypass

    Post summary

    The tweet warns of a critical RCE in WeKnora’s AI DB query tool and urges assessment and prompt application of vendor patches.

    0000033
    2 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30860 (CVSS:9.9, CRITICAL) is Analyzed. WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0...https://nvd.nist.gov/vuln/detail/CVE-2026-30860 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet reports CVE-2026-30860 as critical (CVSS 9.9) and links to the NVD page, but provides no details on exploitation, PoC, or mitigation.

    0000020
    172 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30860 - Critical WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the app... https://www.thehackerwire.com/vulnerability/CVE-2026-30860/ https://t.co/JBbDljOSak

    Post summary

    The tweet announces CVE‑2026‑30860, a critical RCE flaw in WeKnora versions before 0.2.12, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000045
    130 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30860 WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerabil… https://www.cve.org/CVERecord?id=CVE-2026-30860

    Post summary

    CVE-2026-30860 exposes an RCE in WeKnora before version 0.2.12; upgrading to that version mitigates the flaw.

    0000085
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30860: CRITICAL] A critical remote code execution (RCE) vulnerability in WeKnora's database query functionality was patched in version 0.2.12, preventing SQL injection attacks. #cybersecurity#cve,CVE-2026-30860,#cybersecurity https://cvefind.com/CVE-2026-30860

    Post summary

    A critical RCE vulnerability (CVE‑2026‑30860) in WeKnora's database query function has been patched in version 0.2.12, mitigating the SQL injection issue.

    0000063
    599 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30860 - WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool Intel Report: https://ift.tt/hxIKg7m

    Post summary

    A new CVE-2026-30860 is disclosed: it allows remote code execution through an SQL injection bypass in an AI database query tool, but no PoC, exploit, or patch details are provided.

    0000031
    344 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptencentweknora---

Explore more