CVE-2026-33505 describes a high-severity SQL injection vulnerability in Ory Keto versions prior to 26.2.0, specifically within its GetRelationships API. Attackers can exploit this by crafting malicious pagination tokens, particularly if the default or known `secrets.pagination` value is in use, enabling arbitrary SQL query execution. Rated 7.2 High on CVSS, the attack requires network access and high privileges but has low complexity, leading to a complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor are public exploit tools or code available. Community discussion regarding this vulnerability remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.2.0CPE matchmatch criteria | cpe:2.3:a:ory:keto:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.