PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8462 openmeter CVE debrief

A SQL injection vulnerability exists in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms. This vulnerability allows a remote unauthenticated attacker to access or modify metering event data and potentially cause denial of service via crafted user-controlled JSONPath values submitted to the meters API. The vulnerability has been publicly disclosed and defenders should assess exposure and potential impact, especially in environments using OpenMeter OpenMeter versions prior to v1.0.0-beta.228.

Vendor
openmeter
Product
Unknown
CVSS
HIGH 8.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Defenders and security teams responsible for OpenMeter OpenMeter deployments, especially those using versions prior to v1.0.0-beta.228, should assess exposure and potential impact.

Why it matters

CVE-2026-8462 is a SQL injection vulnerability in OpenMeter OpenMeter before v1.0.0-beta.228. Defenders should prioritize verifying exposure, assessing potential impact, and taking remediation actions to prevent potential access or modification of metering event data and denial of service.

  • Potential access to sensitive metering event data
  • Potential modification of metering event data
  • Potential denial of service via crafted JSONPath values
  • Verification of OpenMeter OpenMeter version and exposure

Technical summary

The SQL injection vulnerability in OpenMeter OpenMeter before v1.0.0-beta.228 allows remote unauthenticated attackers to access or modify metering event data and potentially cause denial of service via crafted user-controlled JSONPath values submitted to the meters API. This vulnerability is due to inadequate input validation and sanitization of user-controlled JSONPath values. Defenders should prioritize verifying exposure and assessing potential impact, especially in environments using OpenMeter OpenMeter versions prior to v1.0.0-beta.228.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact, especially in environments using OpenMeter OpenMeter versions prior to v1.0.0-beta.228.

Recommended defensive actions

  • Verify OpenMeter OpenMeter version and update to v1.0.0-beta.228 or later if necessary
  • Restrict access to the meters API
  • Monitor for suspicious activity and potential denial of service
  • Review and validate user-controlled JSONPath values
  • Perform a thorough review of OpenMeter OpenMeter deployments to identify potential exposure
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the SQL injection vulnerability in OpenMeter OpenMeter. However, specific details about exploitation, victims, or business impact are not provided. The vulnerability is confirmed to exist in OpenMeter OpenMeter before v1.0.0-beta.228, and defenders should verify exposure and assess potential impact. Evidence is limited to public sources, and further verification is required to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8462 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8462

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8462 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8462

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/openmeterio/openmeter/pull/4383

    02762ae7-200e-4b20-9b2b-a77d5b8fc4cb

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.