PT-2026-26948 · Unknown · Apconw Aix-Db
Goku
+1
·
Published
2026-03-21
·
Updated
2026-03-22
·
CVE-2026-4530
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
apconw Aix-DB versions up to 1.2.3
Description
A security flaw exists in apconw Aix-DB, specifically within the file
agent/text2sql/rag/terminology retriever.py. Manipulation of the Description argument can lead to SQL injection. The attack requires local access. The exploit has been publicly released. The vendor was contacted but did not respond.Recommendations
Versions prior to 1.2.3 should be updated. As a temporary workaround, consider restricting access to the
terminology retriever.py file to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apconw Aix-Db