Junglewise Threat Intelligence

CVE-2026-63080: Aptabase SQL injection in ClickHouse query backend

CVE-2026-63080 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Executive brief

Aptabase, an open-source analytics platform, contains a security flaw in how it handles data queries for self-hosted deployments. An authenticated user can bypass built-in privacy controls to view analytics data belonging to other organizations or 'tenants' sharing the same server. This could lead to the unauthorized exposure of sensitive event data, device information, and session details across the entire platform.

Technical details

A SQL injection vulnerability exists in the ClickHouseQueryClient of Aptabase due to the improper neutralization of user-supplied filters within Liquid SQL templates. The application interpolates parameters such as EventName, CountryCode, OsName, DeviceModel, AppVersion, and SessionId directly into SQL strings without escaping or parameterization. While the system uses a PREWHERE app_id clause for tenant isolation, an authenticated attacker can inject a UNION ALL statement to execute a secondary SELECT query that lacks the app_id restriction. This allows for cross-tenant data exfiltration across 13 of the 15 stats API endpoints. This issue specifically affects self-hosted deployments using the ClickHouse backend; the managed cloud version using Tinybird is reportedly unaffected.

Affected products

  • Aptabase Aptabase through commit 5a8936852a20c26267ffaefd3544f91e3ca94135

Timeline

  • 2026-07-11: disclosed: Initial researcher disclosure by YoyoChaud
  • 2026-07-21: advisory: CVE published to NVD dataset

References