{"id":"CVE-2026-72565","summary":"Tencent APIJSON - Unauthenticated SQL Injection via @having Operator Map-Form Bypass","details":"A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.","modified":"2026-08-30T08:17:28.598804Z","published":"2026-08-10T10:40:31.650Z","database_specific":{"cna_assigner":"TuranSec","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72565.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72565.json"},{"type":"ADVISORY","url":"https://github.com/Tencent/APIJSON"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72565"},{"type":"ARTICLE","url":"https://github.com/Tencent/APIJSON/blob/master/APIJSONORM/src/main/java/apijson/orm/AbstractSQLConfig.java"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tencent/apijson","events":[{"introduced":"e6fb80bf93ff1c602033cd8bf953e2d4a8bfca53"},{"fixed":"6b7c4d586341d70bd0416a0730e7db16784274ae"}],"database_specific":{"extracted_events":[{"introduced":"7.1.0"},{"last_affected":"8.1.8"},{"introduced":"0"},{"fixed":"8.1.8"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["8.1.7","8.1.6","8.1.3","8.1.0","8.1.0.0","8.0.2","8.0.0","7.9.0","7.8.0","7.7.0","7.6.0","7.5.5","7.4.0","7.1.0"],"database_specific":{"vanir_signatures_modified":"2026-08-30T08:17:28Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/tencent/apijson/commit/6b7c4d586341d70bd0416a0730e7db16784274ae","target":{"file":"APIJSONORM/src/main/java/apijson/Log.java"},"deprecated":false,"digest":{"line_hashes":["220663449420249786445109733648619719450","329301881663103534868311242902731229993","267456243794288181999938471527123932360","155126785880226749086858678909754857445","272452458117127443043881483981042032340","109923065745760581893822695905889281881","129299279609483527067217067000631378494","293334622077782215445263424483401556785"],"threshold":0.9},"id":"CVE-2026-72565-21427d1a","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72565.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}