Description
Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or identifier quoting. Attackers with a self-registered account can substitute arbitrary subqueries to achieve cross-tenant database reads, extract pg_shadow password hashes, read and write arbitrary files, and execute arbitrary code as the postgres OS user by loading attacker-supplied shared objects, with all injected SQL executing at superuser privilege due to the default PostgreSQL role configuration.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection allows cross‑tenant database reads, extraction of password hashes, file read/write, and execution of arbitrary code as the PostgreSQL OS user.
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a classic SQL injection (CWE‑89) where a malicious format query parameter is directly interpolated into the FROM clause of the Reader API. When exploited by an authenticated user, it permits injection of arbitrary SQL, enabling cross‑tenant database reads, extraction of PostgreSQL password hashes, reading and writing arbitrary files, and executing arbitrary code as the PostgreSQL OS user.

Affected Systems

The affected product is Magistrala from absmach for versions prior to 1.0.0. The specific services impacted are the timescale‑reader and postgres‑reader HTTP API endpoints. Users running any release before 1.0.0 are vulnerable, regardless of operating system or deployment environment.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score of <1% shows a low probability of exploitation in the wild. Minimal prerequisites—a registered and authenticated account and knowledge that the Reader API can accept a malicious format parameter—make the vulnerability actionable for attackers with access to the API. The vulnerability is not listed in the CISA KEV catalog. Attackers may inject arbitrary SQL, elevate to superuser privileges set in PostgreSQL, and execute code as the PostgreSQL OS user by loading malicious shared objects. This would result in full database and system compromise. The potential for exploitation is higher in environments where the Reader API is reachable over the network and the default PostgreSQL superuser privileges remain in place; these conditions are inferred from the description and are not directly stated.

Generated by OpenCVE AI on September 20, 2026 at 23:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Magistrala to v1.0.0 or later, which removes the vulnerable code.
  • Restrict access to trusted hosts and users, or disable the API if not required.
  • Reconfigure PostgreSQL to remove the superuser privilege from the role used by Magistrala and prevent loading of arbitrary shared objects by setting appropriate configuration options.

Generated by OpenCVE AI on September 20, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Absmach
Absmach magistrala
Vendors & Products Absmach
Absmach magistrala

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services that allows authenticated attackers to inject arbitrary SQL by supplying a malicious format query parameter that is interpolated directly into the FROM clause without parameterization or identifier quoting. Attackers with a self-registered account can substitute arbitrary subqueries to achieve cross-tenant database reads, extract pg_shadow password hashes, read and write arbitrary files, and execute arbitrary code as the postgres OS user by loading attacker-supplied shared objects, with all injected SQL executing at superuser privilege due to the default PostgreSQL role configuration.
Title Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Absmach Magistrala
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T13:29:55.933Z

Reserved: 2026-08-27T21:39:20.459Z

Link: CVE-2026-82028

cve-icon Vulnrichment

Updated: 2026-09-16T16:11:32.327Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T20:16:54.077

Modified: 2026-09-23T17:17:47.720

Link: CVE-2026-82028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')