Junglewise Threat Intelligence

CVE-2026-50772: Squirro Cognitive Search server-side template injection in password reset

CVE-2026-50772 · Severity: critical · CVSS 9.8 · Published 2026-08-17

Technologies: Squirro Cognitive Search. Vendors: Squirro.

Executive brief

Squirro Cognitive Search is an enterprise search platform that uses AI and machine learning to help organizations find and analyze information across connected data sources. A vulnerability in the password reset email template allows an unauthenticated attacker to execute arbitrary code on the server by injecting a malicious payload, potentially gaining complete control of the application and access to all indexed data.

Affected products

  • Squirro Cognitive Search

Related threats