PT-2026-41893 · Sparx Systems · Sparx Pro Cloud Server
Published
2026-05-19
·
Updated
2026-06-02
·
CVE-2026-42097
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sparx Pro Cloud Server versions 6.1 (build 167) and earlier
Description
Authentication is required based on the requested URL. An attacker can bypass this check by omitting the
model query parameter and providing the model name only within the binary blob of a POST request, which allows for unauthenticated SQL query execution. This may lead to unauthorized database access and data manipulation.Recommendations
Restrict external exposure of the server to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sparx Pro Cloud Server