CVE-2026-64877
A critical flaw in the ticketing REST API allows an authenticated non‑admin user to inject SQL commands. This can expose sensitive data stored in the appliance’s database. No specific product versions are listed in the public data.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
The vulnerability affects the ticketing REST API of the appliance, but no specific CPE entries are provided.
Real-world impact
An attacker who has logged in as a regular user could read confidential information from the database, potentially compromising customer data or internal records.
Why this severity
The CVSS score of 9.6 reflects that the flaw is network‑accessible (AV:N), requires only low effort (AC:L) and low privileges (PR:L), needs no user interaction (UI:N), and can lead to high confidentiality and integrity compromise (C:H/I:H) while leaving availability untouched (A:N).
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 9d agoAdvisory updatedThe NVD record was last revised.