CVE-2026-86123 SQL Chat contains four unauthenticated API endpoints… — CVE Notify — TG.ME

🚨 CVE-2026-86123
SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.

🎖@cveNotify
GitHub
GitHub - sqlchat/sqlchat: Chat-based SQL Client and Editor for the next decade
Chat-based SQL Client and Editor for the next decade - sqlchat/sqlchat
September 5, 2026 37