Junglewise Threat Intelligence

CVE-2026-52469: Crocus SQL injection in DeviceInfoMapper.xml

CVE-2026-52469 · Severity: info · Published 2026-07-21

Executive brief

A security vulnerability has been identified in Crocus version 1.3.44, a software component used for device management. A remote attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive user information or escalate their privileges within the system. This could lead to a full compromise of the application's data and administrative control.

Technical details

A SQL injection vulnerability exists in Crocus v.1.3.44 within the DeviceInfoMapper.xml file. The flaw is specifically an 'order by' injection caused by the insecure use of the ${} syntax in MyBatis/XML mapping, which fails to properly sanitize user-supplied input before incorporating it into database queries. A remote attacker can exploit this to execute arbitrary SQL commands, potentially gaining DBA-level permissions, accessing data from other databases, or extracting sensitive user credentials and transaction history. No patch has been confirmed in the provided advisory.

Affected products

  • Crocus Crocus 1.3.44

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References