Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Read the full article at SecurityWeek →