CVE-2026-41462Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username field at the authentication endpoint to create privileged accounts, read sensitive data, and execute operating system commands if the database user has elevated permissions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-27); latest day: 2
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-27: 3Mentions · 2026-04-28: 1Mentions · 2026-05-01: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-04-27: 3Technical Details · 2026-04-28: 1Technical Details · 2026-05-01: 204-2704-2805-01
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-273
Disclosure2Patch1
2026-04-281
Disclosure1
2026-05-012
Disclosure1General1
Full discourse6 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-41462 (CVSS 9.8): Unauthenticated SQL injection in ProjeQtor login can enable account takeover and deeper compromise. 🔗FOFA Link: https://en.fofa.info/result?qbase64=dGl0bGU9IlByb2plUXRvciI= 🎯692+ Results are found on http://en.fofa.info in the past year. FOFA Query: title="ProjeQtor" 🔖Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-41462 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    A new ProjeQtor login SQL injection (CVE-2026-41462) with CVSS 9.8 is disclosed, enabling account takeover. No PoC, exploit, patch, or active exploitation is reported.

    015045212.8K
    14.4K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-41462 — CVSS 9.8/10 ██████████ ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/4KcrSeu1kt

    Post summary

    The tweet announces a critical SQL injection vulnerability in ProjeQtor and urges users to apply the patch, without detailing exploitation or providing code.

    2001074
    27 followersView on X
  • z3n@zench4n
    General

    The risk isn't just bad prompts; it is unauthorized agency. If an agent is granted access to environments with unpatched flaws like CVE-2026-41462, a single hijacked instruction can lead to unauthenticated SQL injection and total data exfiltration.

    Post summary

    The text highlights that the unpatched CVE‑2026‑41462 can allow unauthenticated SQL injection and full data exfiltration but provides no PoC, exploit code, or patch information.

    1000016
    1.4K followersView on X
  • z3n@zench4n
    Disclosure

    Infrastructure alert: CVE-2026-41462 in ProjeQtor shows unauthenticated SQLi is still a major threat. For AI agents interacting with web apps, this is a direct path to database compromise via agentic tool execution. Validate all input before it hits your backend.

    Post summary

    The post alerts that CVE-2026-41462 in ProjeQtor allows unauthenticated SQL injection, emphasizing the need for input validation as a defensive measure.

    1000016
    1.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41462 ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatena… https://www.cve.org/CVERecord?id=CVE-2026-41462

    Post summary

    The statement announces that ProjeQtor versions 7.0 through 12.4.3 suffer from an unauthenticated SQL injection in their login process, but provides no PoC, exploit code, or patch details.

    0000080
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41462 Unauthenticated SQL Injection in ProjeQtor 7.0 Through 12.4.3 Login Functionality https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41462

    Post summary

    The post announces an unauthenticated SQL Injection vulnerability in ProjeQtor versions 7.0 to 12.4.3, providing the type and affected components but no proof‑of‑concept, exploit code, or patch details.

    0000043
    4.0K followersView on X

Explore more