Junglewise Threat Intelligence

CVE-2026-42100: Sparx Pro Cloud Server denial of service via invalid SQL query

CVE-2026-42100 · Severity: info · CVSS 7.1 · Published 2026-05-19

Technologies: Sparx Systems Pro Cloud Server. Vendors: Sparx Systems.

Executive brief

Sparx Pro Cloud Server, a platform used to host and share Enterprise Architect models, is vulnerable to a denial-of-service attack. An attacker can send a specifically formatted database query that causes the server software to crash unexpectedly. This results in a service outage, preventing users from accessing or collaborating on architectural models until the service is manually restarted.

Technical details

Sparx Pro Cloud Server contains a vulnerability classified as Improper Handling of Syntactically Invalid Structure (CWE-228). An authenticated attacker with low privileges can execute a specially crafted SQL query that the server fails to parse or handle correctly, leading to an unhandled exception and immediate termination of the Pro Cloud Server service. The attack is carried out over the network and requires valid credentials to submit queries to the database interface. While version 6.1 (build 167) and below are confirmed vulnerable, the vendor has not provided a formal patch or confirmed the status of newer versions.

Affected products

  • Sparx Systems Pro Cloud Server All versions through 6.1 (build 167)

Timeline

  • 2026-05-19: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-05-19: advisory: NVD record published

References

Related threats