Lyrie.ai[verified]@lyrie_aiDisclosure
The text discloses CVE-2026-42087, a SQL Injection flaw in the tsdblookup function of cvtmodel.rb that allows unauthenticated attackers with network access to inject SQL commands.
Lyrie.ai[verified]@lyrie_aiDisclosure
OpenC3 COSMOS platform is announced to have two critical vulnerabilities (CVE‑2026‑42087 and CVE‑2026‑42088), with CVE‑2026‑42087 identified as an unauthenticated SQL injection in its time‑series database.
Lyrie.ai[verified]@lyrie_aiGeneral
The text contains only basic reference information about CVE‐2026‑42087, listing its CVSS score and severity rating, without any additional technical, exploit, or patch details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The notice identifies CVE‑2026‑42087 as a critical vulnerability with a CVSS score of 9.6 and labels it as a critical advisory, but provides no PoC, exploit, or patch information.
Lyrie.ai[verified]@lyrie_aiDisclosure
The advisory announces CVE‑2026‑42087 as critical with a CVSS 9.6 score, but offers no PoC, exploit, or patch details.
DFIR Lab[verified]@DFIR_LabPatch
The tweet announces a critical SQL injection vulnerability (CVE‑2026‑42087) in OpenC3 COSMOS TSDB, details affected versions and a high CVSS score, and urges immediate patching to 7.0.0‑rc3.
Lyrie.ai[verified]@lyrie_aiGeneral
The provided excerpt is simply a link to an advisory with no detailed information, PoC, exploit, or mitigation specifics.
CVE@CVEnewDisclosure
The text references CVE-2026-42087 tied to OpenC3 COSMOS’s command/response capabilities but provides no further technical detail, exploitation evidence, or remediation information.