Junglewise Threat Intelligence

CVE-2026-52673: Cboard SQL injection in getDimensionsValues component

CVE-2026-52673 · Severity: info · CVSS 8.8 · Published 2026-06-23

Executive brief

Cboard, a data visualization and business intelligence platform, contains a security flaw in its dashboard component. An attacker can use this vulnerability to run unauthorized database commands, potentially leading to the theft of sensitive business data or full control over the underlying database. This could result in significant data breaches or disruption of data analysis operations.

Technical details

A SQL injection vulnerability exists in the /cboard/dashboard/getDimensionValues.do endpoint of Cboard v.0.4.2 and earlier. The root cause is the backend's use of JDBC Statement.executeQuery() to execute SQL statements constructed via direct concatenation of user-supplied input from the 'query' and 'colmunName' parameters. Because the application fails to use parameterized queries or effective allowlist validation, an authenticated attacker can inject malicious SQL expressions. This can be used to bypass logical conditions, extract sensitive information from the connected data sources, or potentially achieve remote code execution depending on the database configuration.

Affected products

  • Cboard Cboard 0.4.2 and earlier

Timeline

  • 2026-06-18: disclosed: Vulnerability details shared via GitHub Gist.
  • 2026-06-23: advisory: CVE-2026-52673 published.

References