Upwind Security MDR[verified]@UpwindMDRDisclosure
CVE-2026-42097 allows unauthenticated attackers to bypass authentication and inject SQL on Sparx Pro Cloud Server versions 6.1 and earlier; administrators should limit external access and seek vendor patches.
CCB Alert@CCBalertActive Exploitation
The tweet warns that five Sparx Pro Cloud Server vulnerabilities, rated critical to high, are actively exploited; PoC and patch information is available.
DailyCVE@dailycveDisclosure
The post announces a new critical authentication bypass vulnerability (CVE‑2026‑42097) affecting Sparx Pro Cloud Server, but offers no evidence of exploitation, fixes, or additional technical details beyond the basic classification.
CVE@CVEnewDisclosure
The snippet highlights an authentication bypass vulnerability in Sparx Pro Cloud Server, where omitting the 'model' query parameter allows an attacker to send the model name in the binary body, defying authentication checks.