CVE-2026-4593 is a medium-severity SQL injection vulnerability (CVSS 6.3) affecting erupts erupt bis version 1.13.3, specifically within the EruptDataQuery function of its MCP Tool Interface component. This flaw is remotely exploitable with low privileges, potentially leading to low impact on confidentiality, integrity, and availability. While not actively exploited or listed on the KEV, an exploit has been publicly published and is available for use. Despite the availability of an exploit, community discussion and media coverage for this vulnerability are currently very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Erupts | Erupt | 1.13.0, 1.13.1, 1.13.2, 1.13.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.