CVE-2026-82526: R2R 3.6.6 SQL Injection via Vector Index Creation Endpoint

Published Sep 3, 2026
·
Updated

R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser account.

Affected Software

1 affected component
R2R R2R>3.6.6<=3.6.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade R2R to a version that resolves this vulnerability.

    Fixed in 3.6.6
  2. Compensating control

    Disable or restrict access to the vector index creation endpoint to prevent unauthenticated attackers from manipulating the index name parameter and triggering stacked SQL injection.

Event History

Sep 3, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

Any unauthenticated network-accessible attacker can exploit it. No privileges or user interaction are required.

2

What access does successful SQL injection provide?

Injected statements execute under the PostgreSQL superuser account. An attacker can execute arbitrary SQL, including DDL and DML statements, by supplying semicolon-separated commands in the index name.

3

Which deployments are affected?

R2R versions through 3.6.6 are affected. Exposure requires the vector index creation endpoint to be reachable by an attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203