Loading market data...
← Back to CVE feed

CVE-2026-8462

UNKNOWN View on NVD ↗

Description

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.

Published: Sep 16, 2026 11:17 UTC Modified: Sep 16, 2026 18:17 UTC