A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.
History

Fri, 23 Jan 2026 07:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sensitive information disclosure, such as reading system files, and allow for data manipulation or deletion within the application's database, resulting in an application level denial of service.
Title org.hibernate/hibernate-core: Hibernate: Information disclosure and data deletion via second-order SQL injection Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection
First Time appeared Redhat
Redhat amq Broker
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat openshift Ai
Redhat openshift Devspaces
Redhat optaplanner
Redhat red Hat Single Sign On
Redhat satellite
CPEs cpe:/a:redhat:amq_broker:7
cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jboss_enterprise_bpms_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_devspaces:3
cpe:/a:redhat:optaplanner:::el6
cpe:/a:redhat:red_hat_single_sign_on:7
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat amq Broker
Redhat jboss Data Grid
Redhat jboss Enterprise Application Platform
Redhat jboss Enterprise Bpms Platform
Redhat jboss Fuse
Redhat jbosseapxp
Redhat openshift Ai
Redhat openshift Devspaces
Redhat optaplanner
Redhat red Hat Single Sign On
Redhat satellite
References

Tue, 20 Jan 2026 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title org.hibernate/hibernate-core: Hibernate: Information disclosure and data deletion via second-order SQL injection
Weaknesses CWE-89
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2026-01-23T06:31:38.975Z

Updated: 2026-01-23T07:13:43.935Z

Reserved: 2026-01-05T13:18:55.616Z

Link: CVE-2026-0603

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-23T07:15:53.660

Modified: 2026-01-23T07:15:53.660

Link: CVE-2026-0603

cve-icon Redhat

Severity : Important

Publid Date: 2026-01-19T10:10:00Z

Links: CVE-2026-0603 - Bugzilla