BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands.
History

Wed, 20 May 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unsanitized Metric Filters Enable SQL Injection in BillaBear EventRepository

Wed, 20 May 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Billabear
Billabear billabear
Vendors & Products Billabear
Billabear billabear

Tue, 19 May 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unsanitized Metric Filters Enable SQL Injection in BillaBear EventRepository
Weaknesses CWE-89

Tue, 19 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpolated into SQL queries using sprintf() without proper sanitization or identifier quoting. Although filter values are parameterized, the filter identifiers (keys) are not. An authenticated attacker with ROLE_ACCOUNT_MANAGER permissions can exploit this to execute arbitrary SQL commands.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-05-19T00:00:00.000Z

Updated: 2026-05-20T13:50:15.527Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31069

cve-icon Vulnrichment

Updated: 2026-05-20T13:50:10.890Z

cve-icon NVD

Status : Deferred

Published: 2026-05-19T16:16:20.230

Modified: 2026-05-20T14:16:40.150

Link: CVE-2026-31069

cve-icon Redhat

No data.