Executive brief
Sparx Pro Cloud Server, a platform used to host and share Enterprise Architect models, contains a critical security flaw. An unauthenticated attacker can remotely execute arbitrary database commands, potentially leading to the theft of sensitive intellectual property, data corruption, or a complete shutdown of the modeling environment. This vulnerability poses a significant risk to corporate data integrity and confidentiality.
Technical details
A critical SQL injection vulnerability (CWE-89) exists in Sparx Pro Cloud Server version 6.0.163. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the server that are improperly neutralized before being executed against the backend database. Successful exploitation grants the attacker full read and write access to the database, potentially leading to sensitive information disclosure (CWE-200) or complete system compromise. The vulnerability is reachable over the network without user interaction. Users are advised to review the Sparx Systems release notes for version 6.1 for remediation details.
Affected products
- Sparx Systems Pro Cloud Server 6.0.163
Timeline
- 2026-04-17: disclosed
- 2026-04-17: advisory