The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vulnerability in the webhook edit and scanner api endpoints that allow an authenticated attacker to execute arbitrary SQL queries against the MySQL database. Commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8 contains a patch.

Project Subscriptions

Vendors Products
Tarkov Data Manager Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Tarkov
Tarkov tarkov Data Manager
CPEs cpe:2.3:a:tarkov:tarkov_data_manager:*:*:*:*:*:*:*:*
Vendors & Products Tarkov
Tarkov tarkov Data Manager

Wed, 07 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vulnerability in the webhook edit and scanner api endpoints that allow an authenticated attacker to execute arbitrary SQL queries against the MySQL database. Commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8 contains a patch.
Title Tarkov Data Manager has Authenticated SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-07T18:34:40.382Z

Reserved: 2026-01-05T16:44:16.367Z

Link: CVE-2026-21856

cve-icon Vulnrichment

Updated: 2026-01-07T18:34:14.778Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-07T19:15:58.147

Modified: 2026-02-03T16:19:36.620

Link: CVE-2026-21856

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses