Stats Digest Feeds
← Back to all CVEs

CVE-2026-8462

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Sep 16, 2026
Vendor unknown

Description

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to metersΒ API.

References