PatchSiren cyber security CVE debrief
CVE-2026-8462 openmeter CVE debrief
A SQL injection vulnerability exists in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms. This vulnerability allows a remote unauthenticated attacker to access or modify metering event data and potentially cause denial of service via crafted user-controlled JSONPath values submitted to the meters API. The vulnerability has been publicly disclosed and defenders should assess exposure and potential impact, especially in environments using OpenMeter OpenMeter versions prior to v1.0.0-beta.228.
- Vendor
- openmeter
- Product
- Unknown
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-16
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-16
- Advisory updated
- 2026-09-18
Who should care
Defenders and security teams responsible for OpenMeter OpenMeter deployments, especially those using versions prior to v1.0.0-beta.228, should assess exposure and potential impact.
Why it matters
CVE-2026-8462 is a SQL injection vulnerability in OpenMeter OpenMeter before v1.0.0-beta.228. Defenders should prioritize verifying exposure, assessing potential impact, and taking remediation actions to prevent potential access or modification of metering event data and denial of service.
- Potential access to sensitive metering event data
- Potential modification of metering event data
- Potential denial of service via crafted JSONPath values
- Verification of OpenMeter OpenMeter version and exposure
Technical summary
The SQL injection vulnerability in OpenMeter OpenMeter before v1.0.0-beta.228 allows remote unauthenticated attackers to access or modify metering event data and potentially cause denial of service via crafted user-controlled JSONPath values submitted to the meters API. This vulnerability is due to inadequate input validation and sanitization of user-controlled JSONPath values. Defenders should prioritize verifying exposure and assessing potential impact, especially in environments using OpenMeter OpenMeter versions prior to v1.0.0-beta.228.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact, especially in environments using OpenMeter OpenMeter versions prior to v1.0.0-beta.228.
Recommended defensive actions
- Verify OpenMeter OpenMeter version and update to v1.0.0-beta.228 or later if necessary
- Restrict access to the meters API
- Monitor for suspicious activity and potential denial of service
- Review and validate user-controlled JSONPath values
- Perform a thorough review of OpenMeter OpenMeter deployments to identify potential exposure
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the SQL injection vulnerability in OpenMeter OpenMeter. However, specific details about exploitation, victims, or business impact are not provided. The vulnerability is confirmed to exist in OpenMeter OpenMeter before v1.0.0-beta.228, and defenders should verify exposure and assess potential impact. Evidence is limited to public sources, and further verification is required to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8462 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8462
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8462 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8462
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/openmeterio/openmeter/pull/4383
02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.