CVE
CVE-2026-48528
0field notes · 1digest CVSS 9.8
The verdict
Metacat, the data repository platform used in the DataONE network, has a critical unauthenticated SQL injection in its `/cn/v1/object` and `/cn/v2/object` REST endpoints. The `nodeId` parameter goes straight into a PostgreSQL query with zero sanitization, and error messages reflect query results back to the caller. That means attackers can read, insert, update, and delete anything in the database without logging in. Full proof-of-concept exploits exist. CVSS 9.8.
Patch urgency · Patch immediately
Daily digests