CVE-2026-64877
Severity CVSS v4.0:
CRITICAL
Type:
CWE-20
Input Validation
Publication date:
21/07/2026
Last modified:
21/07/2026
Description
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
8.40
Severity 3.x
HIGH



