CVE-2026-86123: SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints

Published Sep 5, 2026
·
Updated

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.

Affected Software

1 affected component
SQL Chat

Event History

Sep 5, 2026
CVE Published
via MITRE·09:59 AM
Data Sourced
via MITRE·09:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker that can reach the affected API endpoints can supply database connection details and SQL queries. No account or user interaction is required.

2

What systems are at risk beyond the SQL Chat server itself?

Databases and other reachable database services on the SQL Chat server's internal network may be exposed because an attacker can direct the server to connect to attacker-specified hosts. This can enable schema enumeration, SQL command execution, and network pivoting.

3

Is there a safe default configuration indicated by the available information?

No. The reported endpoints are described as unauthenticated, and the available information does not identify a configuration setting that restricts them by default.

4

How can I determine whether my deployment is exposed?

Determine whether the /api/connection endpoints are reachable by untrusted networks and whether they accept client-supplied connection parameters without authentication. Review access logs for requests to those endpoints, particularly requests containing unexpected internal hostnames, addresses, or database connection details.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203