Description
kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Database compromise via SQL injection
Action: Immediate Patch
AI Analysis

Impact

kaiten versions from 57.192.20 up to but not including 57.214.26 are vulnerable to SQL injection because dynamic SQL statements are built without proper data validation or the use of parameterized queries or stored procedures, allowing an attacker to inject arbitrary SQL. This flaw can lead to unauthorized data read, modification, or deletion, resulting in loss or alteration of confidential information. The vulnerability is a classic example of injection weaknesses.

Affected Systems

The affected product is kaiten, a data ingestion tool, with impacted versions ranging from 57.192.20 through 57.214.25. Versions prior to 57.192.20 and 57.214.26 or later are not known to be vulnerable.

Risk and Exploitability

EPSS score of 0.00215 indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. However, the nature of the flaw—unsanitized user input in SQL queries—typically carries a high potential for attack if the application is exposed to untrusted data. The likely attack vector is through any endpoint that accepts user-supplied parameters without validation, but specific exploitation steps are not detailed in the advisory. Given these uncertainties, an assessment of the overall risk would be high in environments where kaiten processes sensitive or high-volume data. The CVSS score is 9.9, which denotes critical severity.

Generated by OpenCVE AI on September 22, 2026 at 17:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade kaiten to version 57.214.26 or later where the input validation and parameterized query safeguards are implemented.
  • Restrict or disable any external interfaces that feed data into the susceptible SQL statements until a patch is available.
  • Implement application-layer input validation and substitute dynamic SQL with prepared statements or stored procedures to eliminate direct query construction.

Generated by OpenCVE AI on September 22, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in kaiten Data Ingestion Tool

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Sun, 20 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in kaiten Data Ingestion Tool
Weaknesses CWE-89

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title kaiten SQL Injection Vulnerability in Versions 57.192.20 to 57.214.25
Weaknesses CWE-89

Wed, 16 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title kaiten SQL Injection Vulnerability in Versions 57.192.20 to 57.214.25
Weaknesses CWE-89

Tue, 15 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:13:58.687Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79303

cve-icon Vulnrichment

Updated: 2026-09-22T15:13:12.411Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T15:17:21.827

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T18:00:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')