Junglewise Threat Intelligence

CVE-2026-49344: Sourcentis Mercator authorization bypass in Query Engine

CVE-2026-49344 · Severity: info · CVSS 7.1 · Published 2026-06-19

Executive brief

Mercator is an open-source tool used for mapping and managing information systems. A security flaw in its query engine allows any logged-in user, even those with restricted read-only access, to view sensitive data they should not be able to see, such as user directories and system configurations. Furthermore, attackers can use a specialized technique to slowly extract encrypted user passwords. This could lead to unauthorized access to sensitive corporate data or account takeovers.

Technical details

An authorization bypass exists in Mercator's QueryController::execute() method. While other methods like store() and massDestroy() are protected by authorization gates, the execute() endpoint lacks these checks, allowing any authenticated user (including those with the 'Auditor' role) to submit JSON DSL queries via the Query Engine. This allows unauthorized access to models such as the User model and CMDB objects. Additionally, while the password field is hidden from direct output, it can be used in filter predicates with LIKE conditions. An attacker can exploit this to perform a side-channel attack, observing result counts to reconstruct bcrypt password hashes character by character. The issue is fixed in version 2025.05.19.

Affected products

  • sourcentis Mercator < 2025.05.19

Timeline

  • 2025-05-19: patched: Version 2025.05.19 released to address the vulnerability.
  • 2026-05-25: advisory: GitHub Security Advisory published.
  • 2026-06-19: disclosed: CVE-2026-49344 published to the NVD.

References

Related threats