« Volver al listado

CVE-2026-31069

Estado: AplazadaAlta (8.8)—

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

SQL injection en servicio remoto accesible con autenticación (PR:L). Atacante autenticado con permisos ROLE_ACCOUNT_MANAGER ejecuta SQL arbitrario, permitiendo leer datos (C:H) y modificar información (I:H).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-31069",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-31069",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-20T13:49:12.746377Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-19T16:16:20.230",
  "references": [
    {
      "url": "https://gist.github.com/nedlir/2377ba6e7fa2ad957210b52aa8e400d9",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/nedlir/a50725b94650467f0593b8f4009ae19e",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/BillaBear/billabear",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/nedlir/a50725b94650467f0593b8f4009ae19e",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands."
    },
    {
      "lang": "es",
      "value": "BillaBear (todas las versiones anteriores a enero de 2026) contiene una vulnerabilidad de inyección SQL en el EventRepository. La entrada controlada por el usuario de los nombres de los filtros de métricas y las propiedades de agregación se interpola directamente en las consultas SQL utilizando sprintf() sin una sanitización adecuada o el entrecomillado de identificadores. Aunque los valores de los filtros están parametrizados, los identificadores de los filtros (claves) no lo están. Un atacante autenticado con permisos ROLE_ACCOUNT_MANAGER puede explotar esto para ejecutar comandos SQL arbitrarios."
    }
  ],
  "lastModified": "2026-07-24T12:10:00.210",
  "sourceIdentifier": "cve@mitre.org"
}