PT-2026-94065 · Coze Dev+1 · Coze-Studio

·

CVE-2026-92788

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coze Studio versions prior to 0.5.2
Description Authenticated attackers can execute SQL statements against memory databases of other workspaces to read, insert, or delete data. This occurs because the software fails to validate that table names used in workflow SQL customization nodes belong to the caller's workspace, allowing the enumeration of predictable table identifiers.
Recommendations Update Coze Studio to version 0.5.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92788

Affected Products

Coze-Studio