PT-2026-4327 · Red Hat+1 · Hibernate+1

·

CVE-2026-0603

·

Published

2026-01-23

·

Updated

2026-08-19

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Confluence Data Center versions 6.6.0 through 6.6.0 Confluence Data Center versions 6.13.0 through 6.13.0 Confluence Data Center versions 7.4.0 through 7.4.0 Confluence Data Center versions 7.13.0 through 7.13.0 Confluence Data Center versions 7.19.0 through 7.19.0 Confluence Data Center versions 8.5.0 through 8.5.0 Confluence Data Center versions 8.9.0 through 8.9.0 Confluence Data Center versions 9.0.1 through 9.0.1 Confluence Data Center versions 9.1.0 through 9.1.0 Confluence Data Center versions 9.2.0 through 9.2.22 Confluence Data Center versions 9.3.1 through 9.3.1 Confluence Data Center versions 9.4.0 through 9.4.0 Confluence Data Center versions 9.5.1 through 9.5.1 Confluence Data Center versions 10.0.3 through 10.0.3 Confluence Data Center versions 10.1.0 through 10.1.0 Confluence Data Center versions 10.2.0 through 10.2.14
Description A second-order SQL injection exists in Hibernate when the InlineIdsOrClauseBuilder is used. A remote attacker with low privileges can exploit this by providing specially crafted, unsanitized non-alphanumeric characters in the ID column. This allows an authenticated attacker to forward malicious queries to the database, potentially leading to the disclosure of sensitive information, such as reading system files, and the manipulation or deletion of database records, which may result in an application-level denial of service.
Recommendations Upgrade Confluence Data Center version 9.2 to 9.2.23 or later. Upgrade Confluence Data Center version 10.2 to 10.2.15 or later. Upgrade all other affected versions of Confluence Data Center to the latest available release.

Exploit

Fix

DoS

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0603
GHSA-2P5W-CVG5-GC5C
RHSA-2026:4915
RHSA-2026:4916
RHSA-2026:4917
RHSA-2026:6011
RHSA-2026:6012

Affected Products

Confluence
Hibernate