CVE-2026-32949 is a high-severity Server-Side Request Forgery (SSRF) vulnerability impacting SQLBot versions prior to 1.7.0. This flaw allows an unauthenticated attacker to retrieve arbitrary system and application files from the server. Exploitation occurs by configuring a forged MySQL data source that, during a connectivity check, forces the target to read and transmit local files via a malicious LOAD DATA LOCAL INFILE command from a rogue MySQL server. The vulnerability carries a CVSSv3 score of 7.5 (High) due to its network attack vector, low complexity, and high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:fit2cloud:sqlbot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.