CVE-2026-33505Disclosure(ory / keto)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ory keto systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL injection due to flaws in its pagination implementation. Pagination tokens are encrypted using the secret configured in `secrets.pagination`. An attacker who knows this secret can craft their own tokens, including malicious tokens that lead to SQL injection. If this configuration value is not set, Keto falls back to a hard-coded default pagination encryption secret. Because this default value is publicly known, attackers can generate valid and malicious pagination tokens manually for installations where this secret is not set. This issue can be exploited when GetRelationships API is directly or indirectly accessible to the attacker, the attacker can pass a raw pagination token to the affected API, and the configuration value `secrets.pagination` is not set or known to the attacker. An attacker can execute arbitrary SQL queries through forged pagination tokens. As a first line of defense, immediately configure a custom value for `secrets.pagination` by generating a cryptographically secure random secret. Next, upgrade Keto to a fixed version, 26.2.0 or later, as soon as possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • keto

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
keto

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-29: 103-2603-29
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-03-291
General1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    General

    A SQL injection vulnerability (CVE-2026-33505) in `Ory Keto` allows data manipulation via forged pagination tokens. Monitor for official patch details. #OryKeto #SQLi #infosec https://www.pulsepatch.io/posts/cve-2026-33505-ory-keto-sql-injection

    Post summary

    The post reports a SQL injection vulnerability (CVE-2026-33505) in Ory Keto, describing how it can be exploited via forged pagination tokens, and advises watching for official patch updates.

    0000147
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33505 Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelationships API in Ory Keto is vulnerable to SQL … https://www.cve.org/CVERecord?id=CVE-2026-33505

    Post summary

    The post announces an SQL‑injection vulnerability in Ory Keto’s GetRelationships API before v26.2.0, noting that the issue is addressed in that version, but provides no PoC, exploit code, or evidence of active exploitation.

    00000167
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33505 - Ory Keto has a SQL injection via forged pagination tokens Intel Report: https://ift.tt/GUuZ5It

    Post summary

    CVE-2026-33505 is a newly disclosed SQL injection flaw in Ory Keto that can be triggered through forged pagination tokens.

    0000025
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporyketo---

Explore more