CVE-2026-42097Disclosure(sparxsystems / pro_cloud_server)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch sparxsystems pro_cloud_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pro_cloud_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-19); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
pro_cloud_server

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-21: 1Mentions · 2026-06-02: 1PoC Mentioned / Linked · 2026-05-21: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-21: 1Technical Details · 2026-06-02: 105-1905-2106-02
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure2
2026-05-211
Active Exploitation1
2026-06-021
Disclosure1
Full discourse4 posts
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: 1 critical, 4 High, all actively exploited vulnerabilities in #Sparx Pro Cloud Server, Enterprise Architect #CVE-2026-42096 #CVE-2026-42097 #CVE-2026-42098 #CVE-2026-42099 #CVE-2026-42100 CVSS: 9.3-7.1 #PoC available #Patch #Patch #Patch

    Post summary

    The tweet warns that five Sparx Pro Cloud Server vulnerabilities, rated critical to high, are actively exploited; PoC and patch information is available.

    01010224
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Sparx Pro Cloud Server Authentication Bypass / SQL Injection (CVE-2026-42097) Sparx Pro Cloud Server may allow unauthenticated attackers to execute SQL queries by omitting the model query parameter and supplying the model name within a crafted POST request body, bypassing authentication checks tied to the requested URL. Successful exploitation may lead to unauthorized database access and data manipulation. 👉 Versions 6.1 (build 167) and below were confirmed vulnerable. Administrators should restrict external exposure and monitor vendor advisories for updates and remediation guidance.

    Post summary

    CVE-2026-42097 allows unauthenticated attackers to bypass authentication and inject SQL on Sparx Pro Cloud Server versions 6.1 and earlier; administrators should limit external access and seek vendor patches.

    0002072
    255 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Sparx Pro Cloud Server, Authentication Bypass, #CVE-2026-42097 (Critical) -DC-Jun2026-118 https://dailycve.com/sparx-pro-cloud-server-authentication-bypass-cve-2026-42097-critical-dc-jun2026-118/

    Post summary

    The post announces a new critical authentication bypass vulnerability (CVE‑2026‑42097) affecting Sparx Pro Cloud Server, but offers no evidence of exploitation, fixes, or additional technical details beyond the basic classification.

    0000033
    209 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42097 Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blo… https://www.cve.org/CVERecord?id=CVE-2026-42097

    Post summary

    The snippet highlights an authentication bypass vulnerability in Sparx Pro Cloud Server, where omitting the 'model' query parameter allows an attacker to send the model name in the binary body, defying authentication checks.

    00000125
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsparxsystemspro_cloud_server---

Explore more