THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86123 (HIGH 8.7) — SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into

[NVD] CVE-2026-86123 (HIGH 8.7) — SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into

mednvdPublished 2026-09-05

CVE-2026-86123 CVSS: 8.7 HIGH Published: 2026-09-05T10:16:43.750

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86123