PatchDayAlert

CVE

CVE-2026-48528

0field notes · 1digest CVSS 9.8

The verdict

Metacat, the data repository platform used in the DataONE network, has a critical unauthenticated SQL injection in its `/cn/v1/object` and `/cn/v2/object` REST endpoints. The `nodeId` parameter goes straight into a PostgreSQL query with zero sanitization, and error messages reflect query results back to the caller. That means attackers can read, insert, update, and delete anything in the database without logging in. Full proof-of-concept exploits exist. CVSS 9.8.

Patch urgency · Patch immediately


Daily digests