Description
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
Published: 2026-09-16
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a SQL injection flaw in the ClickHouse-backed meter definitions of OpenMeter. An attacker can supply crafted JSONPath values to the meters API, allowing remote execution of arbitrary SQL statements against the ClickHouse database. This can lead to unauthorized reading or modification of metering event data and may cause denial of service by overloading or corrupting the database. The weakness is a classic injection flaw identified as CWE‑89.

Affected Systems

The issue affects all installations of OpenMeter (openmeter:openmeter) running any version prior to 1.0.0‑beta.228. No platform‑specific limitations were noted, so the vulnerability is present on every supported operating system.

Risk and Exploitability

The vulnerability has a CVSS score of 8.9, indicating high severity. The EPSS score is below 1 %, implying low expected exploitation frequency, and it is not listed in the CISA KEV catalog. Attackers would need only network access to the exposed meters API and no authentication, making the route relatively straightforward but still opportunistic. Given the high severity and the fact that the attacker can affect data integrity, confidentiality, and availability, the overall risk warrants prompt attention.

Generated by OpenCVE AI on September 18, 2026 at 09:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 1.0.0‑beta.228 or later, which contains a fix for the SQL injection issue.
  • If an immediate upgrade is impossible, block unauthenticated access to the meters API from external networks or restrict it to trusted IP ranges using firewall or ACL rules.
  • Implement input sanitization or parameterized queries for JSONPath handling to remove the injection vector, and apply additional checks for user‑controlled data before it is used in SQL statements.

Generated by OpenCVE AI on September 18, 2026 at 09:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wc3v-3457-c8cm OpenMeter: SQL injection through meter creation
History

Thu, 17 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Openmeter
Openmeter openmeter
Vendors & Products Openmeter
Openmeter openmeter

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
Title OpenMeter SQL Injection in ClickHouse-backed Meter Definitions
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Openmeter Openmeter
cve-icon MITRE

Status: PUBLISHED

Assigner: Kong

Published:

Updated: 2026-09-16T17:46:37.602Z

Reserved: 2026-05-13T10:00:57.228Z

Link: CVE-2026-8462

cve-icon Vulnrichment

Updated: 2026-09-16T17:46:26.173Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T11:17:11.327

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-8462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')