Junglewise Threat Intelligence

CVE-2026-49490: OpenCATS SQL injection in DataGrid filter handling

CVE-2026-49490 · Severity: high · CVSS 8.1 · Published 2026-05-31

Technologies: OpenCATS. Vendors: OpenCATS.

Executive brief

OpenCATS, an open-source applicant tracking system, contains a security flaw in how it handles data filters. An authorized user can bypass security restrictions to run unauthorized database commands. This could allow an attacker to view sensitive candidate information or modify database records, potentially compromising the integrity of the recruitment platform.

Technical details

An SQL injection vulnerability exists in OpenCATS starting from version 0.9.1a within the DataGrid filter handling component. The root cause is a failure to enforce 'filterable => false' restrictions on the server side for the 'Tags' column in the Candidates DataGrid. An authenticated attacker can manipulate filter requests to target this non-filterable column, bypassing intended restrictions to inject malicious SQL syntax. This allows for unauthorized data extraction or modification. While a patch has been described (skipping server-side processing for non-filterable columns), a specific patched version number was not confirmed in the advisory text.

Affected products

  • OpenCATS OpenCATS >= 0.9.1a

Timeline

  • 2026-04-23: advisory: GitHub Security Advisory published
  • 2026-05-31: disclosed: NVD publication date

References

Related threats