PatchSiren

aptabase CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH aptabase CVE published 2026-07-21

CVE-2026-63080

CVE-2026-63080 is a SQL injection vulnerability in Aptabase's ClickHouse query backend. The vulnerability allows authenticated attackers to read event data across all tenants by injecting unsanitized filter parameters into Liquid SQL templates. Attackers can supply malicious values through EventName, CountryCode, OsName, DeviceModel, AppVersion, or SessionId parameters to inject a UNION ALL statement that [truncated]