PT-2026-2029 · Unknown+1 · Questdb Ui+1

·

CVE-2026-0824

·

Published

2026-01-10

·

Updated

2026-01-10

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions questdb ui versions up to 1.11.9
Description A security flaw exists in the Web Console component of questdb ui, potentially leading to cross-site scripting. The issue is remotely exploitable, and an exploit has been publicly released. The vulnerability involves manipulation of an unknown function within the Web Console.
Recommendations Upgrade to version 1.11.10 to address this issue. Upgrade to QuestDB 9.3.0 to address this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0824
GHSA-XF94-H87H-G9WR

Affected Products

Questdb
Questdb Ui