Junglewise Threat Intelligence

CVE-2026-12206: Grit42 Grit SQL injection in DataTableEntity

CVE-2026-12206 · Severity: medium · CVSS 6.3 · Published 2026-06-15

Executive brief

A security vulnerability has been identified in Grit42 Grit, a platform used for managing scientific laboratory data and assays. An attacker could exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive research data. This issue is particularly concerning as a functional exploit has been made publicly available, and the software vendor has not yet released a fix.

Technical details

A SQL injection vulnerability exists in Grit42 Grit versions up to 0.11.0 within the Grit::Assays::DataTableEntity function. The flaw is located in the Ruby on Rails model file 'modules/assays/backend/app/models/grit/assays/data_table_entity.rb'. A remote attacker with low-level privileges can manipulate database queries by sending specially crafted requests to the affected endpoint. This can lead to unauthorized data exfiltration, modification, or deletion. While the vulnerability is confirmed and a public exploit exists, the vendor has reportedly not responded to disclosure attempts, and no official patch is currently available.

Affected products

  • Grit42 Grit up to 0.11.0

Timeline

  • 2026-06-15: advisory: Initial disclosure via VulDB and NVD
  • 2026-06-15: disclosed: Public exploit code released on GitHub

References

Related threats