CVE-2026-5587Disclosure

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py of the component Refiner Agent. The manipulation leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-05: 3PoC Mentioned / Linked · 2026-04-05: 1Exploit Tool / Code · 2026-04-05: 1Technical Details · 2026-04-05: 304-05
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    PoC

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5587 - wbbeyourself MAC-SQL Refiner Agent http://agents.py _execute_sql sql injection Intel Report: https://ift.tt/AmKbZwP

    Post summary

    The post is a threat alert that shares a code sample (http://agents.py) demonstrating a SQL injection (CVE‑2026‑5587) but does not mention active exploitation or a patch.

    0000034
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5587 A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py… https://www.cve.org/CVERecord?id=CVE-2026-5587 ----- Traducción: CVE-2026-5587 Se … http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE‑2026‑5587 in wbbeyourself MAC‑SQL, providing a link to the CVE record and technical details about the vulnerable function, but contains no PoC, exploitation, or patch information.

    0000031
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5587 A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py… https://www.cve.org/CVERecord?id=CVE-2026-5587

    Post summary

    CVE-2026-5587 was identified in wbbeyourself MAC‑SQL, impacting the _execute_sql function in core/agents.py; no PoC, exploit, or mitigation information is provided.

    00000363
    56.8K followersView on X

Explore more