CVE-2026-35168Disclosure(devcode / openstamanager)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch devcode openstamanager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database conflict resolution feature (op=risolvi-conflitti-database) that accepts a JSON array of SQL statements via POST and executes them directly against the database without any validation, allowlist, or sanitization. An authenticated attacker with access to the Aggiornamenti module can execute arbitrary SQL statements including CREATE, DROP, ALTER, INSERT, UPDATE, DELETE, SELECT INTO OUTFILE, and any other SQL command supported by the MySQL server. Foreign key checks are explicitly disabled before execution (SET FOREIGN_KEY_CHECKS=0), further reducing database integrity protections. This issue has been patched in version 2.10.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openstamanager

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-02); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openstamanager

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-05: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 104-0204-05
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1Patch1
2026-04-051
General1
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-35168 - High OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database ... https://www.thehackerwire.com/vulnerability/CVE-2026-35168/ https://t.co/Sp7uDYAB57

    Post summary

    The text references CVE-2026-35168 and links to a vulnerability page but provides no PoC, exploit, active exploitation, patch, or technical details.

    0000057
    161 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35168 OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAMan… https://www.cve.org/CVERecord?id=CVE-2026-35168

    Post summary

    The note refers to CVE-2026-35168 impacting OpenSTAManager’s Updates module before version 2.10.2 but offers no further technical, exploit, or remediation details.

    00000115
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35168: HIGH] Critical security vulnerability patched in OpenSTAManager v2.10.2. Attackers could execute arbitrary SQL statements due to lack of validation, posing serious cyber threats.#cve,CVE-2026-35168,#cybersecurity https://cvefind.com/CVE-2026-35168

    Post summary

    The text announces that CVE‑2026‑35168, an arbitrary SQL injection vulnerability, has been patched in OpenSTAManager v2.10.2; no PoC, exploit code, or active exploitation details are provided.

    0000038
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdevcodeopenstamanager---

Explore more