CVE-2026-64877: Input Validation
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SC202607.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64877?
The severity of CVE-2026-64877 is critical with a CVSS score of 9.6.
How do I fix CVE-2026-64877?
To fix CVE-2026-64877, ensure that input validation is properly implemented in the ticketing REST API to prevent SQL injection.
Who is affected by CVE-2026-64877?
CVE-2026-64877 affects authenticated non-admin users who can exploit the SQL injection vulnerability in the ticketing REST API.
What kind of vulnerability is CVE-2026-64877?
CVE-2026-64877 is a SQL injection vulnerability related to input validation.
What data can be accessed through CVE-2026-64877?
CVE-2026-64877 allows an attacker to access sensitive data stored in the appliance database.