Red Hat · Hibernate · CVE-2026-0603
**Name of the Vulnerable Software and Affected Versions**
Confluence Data Center versions 6.6.0 through 6.6.0
Confluence Data Center versions 6.13.0 through 6.13.0
Confluence Data Center versions 7.4.0 through 7.4.0
Confluence Data Center versions 7.13.0 through 7.13.0
Confluence Data Center versions 7.19.0 through 7.19.0
Confluence Data Center versions 8.5.0 through 8.5.0
Confluence Data Center versions 8.9.0 through 8.9.0
Confluence Data Center versions 9.0.1 through 9.0.1
Confluence Data Center versions 9.1.0 through 9.1.0
Confluence Data Center versions 9.2.0 through 9.2.22
Confluence Data Center versions 9.3.1 through 9.3.1
Confluence Data Center versions 9.4.0 through 9.4.0
Confluence Data Center versions 9.5.1 through 9.5.1
Confluence Data Center versions 10.0.3 through 10.0.3
Confluence Data Center versions 10.1.0 through 10.1.0
Confluence Data Center versions 10.2.0 through 10.2.14
**Description**
A second-order SQL injection exists in Hibernate when the `InlineIdsOrClauseBuilder` is used. A remote attacker with low privileges can exploit this by providing specially crafted, unsanitized non-alphanumeric characters in the ID column. This allows an authenticated attacker to forward malicious queries to the database, potentially leading to the disclosure of sensitive information, such as reading system files, and the manipulation or deletion of database records, which may result in an application-level denial of service.
**Recommendations**
Upgrade Confluence Data Center version 9.2 to 9.2.23 or later.
Upgrade Confluence Data Center version 10.2 to 10.2.15 or later.
Upgrade all other affected versions of Confluence Data Center to the latest available release.