Junglewise Threat Intelligence

CVE-2026-0603: Hibernate ORM second-order SQL injection in InlineIdsOrClauseBuilder

CVE-2026-0603 · Severity: high · CVSS 8.3 · Published 2026-01-23

Technologies: Red Hat Fuse 7, Red Hat AMQ Broker, Red Hat Single Sign-On 7. Vendors: Red Hat, Maven.

Executive brief

A security vulnerability has been identified in Hibernate, a widely used tool for managing database data in Java applications. An attacker with low-level access could use specially crafted input to manipulate database queries, potentially allowing them to view sensitive files, modify or delete data, or cause the application to crash. This could lead to significant data breaches or service outages for organizations using affected versions of Red Hat JBoss and other enterprise platforms.

Technical details

A second-order SQL injection vulnerability exists in Hibernate ORM's InlineIdsOrClauseBuilder. The flaw is triggered when the application processes unsanitized non-alphanumeric characters provided in the ID column. A remote attacker with low privileges can exploit this by injecting malicious SQL fragments that are later executed by the database engine. Successful exploitation can lead to unauthorized sensitive information disclosure (including reading system files via database functions), data manipulation, or data deletion, potentially resulting in an application-level denial of service. Red Hat has released security updates (e.g., RHSA-2026:4915) for JBoss EAP and related products to address this issue.

Affected products

  • Hibernate Hibernate ORM 5.3.38-1.Final and earlier versions used in Red Hat JBoss EAP 7.4.24
  • Red Hat JBoss Enterprise Application Platform 7.4.24
  • Red Hat AMQ Broker 7
  • Red Hat Fuse 7
  • Red Hat Process Automation 7
  • Red Hat Single Sign-On 7

Timeline

  • 2026-01-23: disclosed: CVE published
  • 2026-03-18: patched: Red Hat released security advisories and patches for JBoss EAP 7.4.24

References

Related threats