Junglewise Threat Intelligence

CVE-2026-42096: Sparx Systems Pro Cloud Server broken access control in database communication

CVE-2026-42096 · Severity: info · CVSS 8.7 · Published 2026-05-19

Technologies: Sparx Systems Pro Cloud Server. Vendors: Sparx Systems.

Executive brief

Sparx Pro Cloud Server, a platform used to host and share Enterprise Architect models, contains a security flaw in how it handles database communications. An attacker with low-level access to the system can bypass security checks to run unauthorized commands directly against the underlying database. This could lead to the theft of sensitive project data, unauthorized modification of models, or disruption of the modeling environment.

Technical details

Sparx Pro Cloud Server is vulnerable to incorrect authorization (CWE-863) within its database communication component. Due to a lack of sufficient permission checks, an authenticated user with low privileges can bypass intended restrictions to execute arbitrary SQL queries within the context of the database user. This allows for full read and write access to the repository data. The vulnerability was confirmed in version 6.1 (build 167) and earlier; the vendor has not provided details on a fix or the full range of affected versions.

Affected products

  • Sparx Systems Pro Cloud Server All versions through 6.1 (build 167) confirmed; later versions potentially affected

Timeline

  • 2026-05-19: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-05-19: advisory: NVD record published

References

Related threats