CVE-2026-13337: SQL Injection
Published Sep 1, 2026
·Updated
CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.
Affected Software
1 affected component
NetBotz
Event History
Sep 1, 2026
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionWeakness
Frequently Asked Questions
1
Does exploiting this issue require an authenticated account?
Yes. The issue is described as requiring a malicious user to be logged in to NetBotz through either the web-service interface or the web UI.
2
Which NetBotz interfaces are relevant for exposure?
The affected attack paths are the web-service interface and the web UI. The provided information does not identify any other interfaces or unauthenticated exploitation path.