Description
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
Published: 2026-07-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in SQLite before the Fossil check‑in 869a51ae84df allows a local attacker to obtain sensitive information by manipulating the Session Extension changeset concat/changegroup merge path. The flaw is a buffer‑access weakness that can leak confidential data stored in the database to the user executing the database.

Affected Systems

The vulnerability affects the SQLite database engine. Any application that incorporates a SQLite build released prior to the check‑in, regardless of vendor, is potentially impacted.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium‑to‑high severity vulnerability, while the EPSS score of < 1% shows a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, meaning no publicly known exploits exist. An attacker would need local file‑system access and the ability to influence the Session Extension merge path; the attack remains local and requires sufficient privileges to invoke or modify the database engine.

Generated by OpenCVE AI on July 28, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update SQLite to a version that includes the commit 869a51ae84df or a later release.
  • Reduce local user rights so that only trusted users can access SQLite database files.
  • Monitor for abnormal Session Extension changes and investigate unauthorized modifications.

Generated by OpenCVE AI on July 28, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title SQLite Local Information Disclosure via Session Extension Changeset Merge Path

Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title SQLite Local Information Disclosure via Session Extension Changeset Merge Path

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension Buffer Read Allows Local Information Disclosure

Wed, 15 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension Buffer Read Allows Local Information Disclosure

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Buffer Over-read in SQLite Session Extension Merge Path

Sun, 12 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via Buffer Over-read in SQLite Session Extension Merge Path

Sat, 11 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via SQLite Session Extension Merge Path Vulnerability

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Information Disclosure via SQLite Session Extension Merge Path Vulnerability

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title SQLite Local Information Disclosure via Session Extension Merge Path

Thu, 09 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title SQLite Local Information Disclosure via Session Extension Merge Path

Wed, 08 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-126
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Sqlite
Sqlite sqlite
Vendors & Products Sqlite
Sqlite sqlite

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AC:L/AV:L/A:H/C:L/I:N/PR:N/S:U/UI:R'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T20:12:52.184Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50813

cve-icon Vulnrichment

Updated: 2026-07-08T20:12:18.793Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses