PT-2026-4327 · Red Hat · Hibernate

Christiaan Swiers

+3

·

Published

2026-01-23

·

Updated

2026-04-27

·

CVE-2026-0603

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Hibernate (affected versions not specified)
Description A flaw exists in Hibernate that allows a remote attacker with low privileges to exploit a second-order SQL injection. The issue occurs when specially crafted, unsanitized non-alphanumeric characters are provided in the ID column while using the InlineIdsOrClauseBuilder. Successful exploitation could lead to sensitive information disclosure, including the ability to read system files, and allow for data manipulation or deletion within the application's database, potentially resulting in an application-level denial of service. A second-order SQL injection occurs when an application receives data from a trusted source but does not properly sanitize it before using it in a database query. The InlineIdsOrClauseBuilder is a component used to construct SQL queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-0603
GHSA-2P5W-CVG5-GC5C
RHSA-2026:4915
RHSA-2026:4916
RHSA-2026:4917
RHSA-2026:6011
RHSA-2026:6012

Affected Products

Hibernate