HIGH
Tranquil_IT
CVE published 2026-08-31
CVE-2026-75132
A SQL injection vulnerability exists in WAPT Server versions 2.6.1.17834 and earlier. The vulnerability is located in the `columns` parameter of the GET `/api/v3/hosts` endpoint. An authenticated user with read-only privileges can exploit this vulnerability to inject arbitrary PostgreSQL expressions, bypass host scope restrictions, and access information from other rows or tables within the database.