Junglewise Threat Intelligence

CVE-2026-5587: wbbeyourself MAC-SQL SQL injection in Refiner Agent

CVE-2026-5587 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Executive brief

wbbeyourself MAC-SQL is a software component used for database interactions within the Refiner Agent system. A security vulnerability has been identified that allows attackers to inject malicious database commands. If exploited, this could allow an unauthorized user to view, modify, or delete sensitive data stored in the database, potentially leading to a full compromise of the application's information.

Technical details

A SQL injection vulnerability exists in the wbbeyourself MAC-SQL component up to commit 31a9df5e0d520be4769be57a4b9022e5e34a14f4. The flaw is located in the _execute_sql function within core/agents.py of the Refiner Agent component. An attacker with low-level privileges can exploit this via the network by sending crafted input that manipulates SQL queries. This can result in unauthorized data access or modification. While the vendor was notified, no official patch has been confirmed, and the project follows a rolling release model. A public exploit is currently available.

Affected products

  • wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4

Timeline

  • 2026-04-05: disclosed: Initial disclosure date
  • 2026-04-05: advisory: VulDB advisory published

References