PT-2026-41892 · Sparx Systems · Pro Cloud Server

Published

2026-05-19

·

Updated

2026-06-02

·

CVE-2026-42096

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sparx Pro Cloud Server versions 6.1 (build 167) and earlier
Description Broken Access Control exists in the communication with the database. Due to a lack of permission checks, a low privileged user can execute arbitrary SQL queries within the database user context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42096

Affected Products

Pro Cloud Server