CRITICAL
9.8 CVE-2026-82526 Published 3 Sept 2026
R2R SQL Injection Vulnerability
Worried this affects one of your servers?
R2R versions through 3.6.6 are affected by a stacked SQL injection vulnerability.
Attackers can execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint.
The index name is directly interpolated into a CREATE INDEX statement, allowing for arbitrary DDL and DML execution under the PostgreSQL superuser account.
Reference: CVE-2026-82526 on NVD
← Back to Security News