Junglewise Threat Intelligence

CVE-2026-18719: cemtan sar2html SQL injection in Search component

CVE-2026-18719 · Severity: medium · CVSS 6.3 · Published 2026-08-04

Executive brief

sar2html is a system activity reporting tool that analyzes performance data. A SQL injection vulnerability in its Search feature allows remote attackers to manipulate database queries, potentially exposing sensitive performance metrics and system information without authentication. The exploit code is publicly available.

Technical details

The vulnerability is a SQL injection in the Search component of sar2html, specifically in the sar2html.py file. By manipulating the Search argument, an attacker can inject arbitrary SQL commands into database queries. The attack is remotely exploitable and requires no authentication or user interaction. A successful exploit allows an attacker to read, modify, or exfiltrate data from the underlying database. A vendor patch is not currently available despite early disclosure.

Affected products

  • cemtan sar2html 4.0.0

Timeline

  • 2026-08-04: disclosed
  • other: Exploit code is publicly available

References