CVE-2026-88397: SQL Injection
Published Oct 5, 2026
·Updated
ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.
Affected Software
1 affected component
ApiAdmin ApiAdmin<=5.0
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
ApiAdmin version 5.0 and earlier are affected by SQL injection in the user-list endpoint GET /admin/User/getUsers when processing the gid parameter.
2
What access does an attacker need to attempt exploitation?
The issue is reachable through the GET /admin/User/getUsers endpoint, but the available data does not state whether authentication or administrative access is required.
3
How can I check whether my instance may be exposed?
Identify the deployed ApiAdmin version and determine whether GET /admin/User/getUsers is present. Instances running version 5.0 or earlier should treat requests containing the gid parameter as potentially vulnerable.