SECURITYCRITICALCVE-2026-33615

CVE-2026-33615: Critical Unauthenticated SQL Injection in setinfo Endpoint

A critical unauthenticated SQL injection vulnerability (CVSS 9.1) in the setinfo endpoint allows remote attackers to corrupt data and cause denial of...

Dylan H.

Security Team

April 3, 2026
3 min read
CVE-2026-33615: Critical Unauthenticated SQL Injection in setinfo Endpoint

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Affected product — setinfo endpoint (see vendor advisory)

Executive Summary

CVE-2026-33615 is a critical unauthenticated SQL injection vulnerability affecting a product's setinfo endpoint. The flaw allows a remote, unauthenticated attacker to manipulate a SQL UPDATE command through improper neutralization of special elements, resulting in a total loss of integrity and availability.

CVSS Score: 9.1 (Critical)

No authentication is required to exploit this vulnerability. Attackers who can reach the affected endpoint over the network can immediately abuse the injection to corrupt or destroy stored data.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-33615
CVSS Score9.1 (Critical)
TypeSQL Injection (CWE-89)
Attack VectorNetwork
Privileges RequiredNone (Unauthenticated)
User InteractionNone
Endpoint/setinfo (SQL UPDATE context)
ImpactTotal integrity & availability loss

Technical Details

The vulnerability exists in the setinfo endpoint, which constructs a SQL UPDATE query without properly sanitizing or parameterizing user-supplied input. An attacker can inject arbitrary SQL syntax into the query, enabling them to:

  • Overwrite arbitrary data in any accessible table
  • Truncate or drop database tables, causing complete availability loss
  • Exfiltrate data via error-based or time-based blind injection techniques
  • Bypass access controls enforced at the application layer by directly manipulating backend records
Vulnerable query pattern (simplified):
  UPDATE table SET field = '<USER_INPUT>'
                             ^--- injection point

Attack payload example:
  value'; UPDATE users SET password='attacker' WHERE '1'='1

Because the endpoint requires no authentication, exploitation requires only network access to the target service — making internet-exposed instances trivially compromisable.


Impact Assessment

Impact CategorySeverity
Data IntegrityCritical — arbitrary record modification
AvailabilityCritical — data deletion/corruption possible
ConfidentialityHigh — data exfiltration via blind SQLi
Authentication RequiredNone
ComplexityLow — straightforward injection

The CVSS base score of 9.1 reflects the combination of no authentication requirement, network-accessible attack vector, and the potential for complete data loss.


Affected Versions

Refer to the official vendor advisory for a complete list of affected product versions. The vulnerability was published to the NVD on 2026-04-02.


Remediation

Immediate Steps

  1. Apply vendor patch as soon as it becomes available — check the vendor's security advisory
  2. Restrict network access to the setinfo endpoint — firewall or ACL rules should block untrusted sources from reaching the endpoint
  3. Deploy a WAF rule to block SQL injection patterns targeting the affected endpoint
  4. Audit database logs for suspicious UPDATE activity that may indicate prior exploitation

If No Patch Is Available

MITIGATIONS:
- Block external access to the setinfo endpoint at the network perimeter
- Enable database activity monitoring to alert on unexpected UPDATE statements
- Implement input validation at the reverse proxy layer (WAF)
- Rotate all database credentials as a precaution if the endpoint was exposed

Detection Indicators

IndicatorDescription
Anomalous SQL UPDATE statementsPayloads containing quotes, semicolons, or SQL keywords
Unexpected POST requests to /setinfoHigh-volume or malformed requests
Database table modificationsUnexpected changes to records outside normal application flow
Application errorsSQL syntax errors logged after abnormal input

References