PT-2026-66612 · Kamaji · Kamaji

CVE-2026-62845

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kamaji versions prior to 26.7.4-edge
Description The PostgreSQL and MySQL datastore drivers build Data Definition Language (DDL) statements by interpolating user-supplied DataStoreUsername and DataStoreSchema directly into SQL using fmt.Sprintf without escaping identifiers. Due to a lack of format validation, a value containing a quote character allows an attacker to break out of the quoted identifier, leading to SQL injection executed via the root connection to the shared datastore. DDL is a set of SQL commands used to define the database structure.
Recommendations Update to version 26.7.4-edge.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62845
GHSA-R47V-PPWP-FH4R

Affected Products

Kamaji