Junglewise Threat Intelligence

CVE-2026-82028: Magistrala SQL injection in timescale-reader and postgres-reader

CVE-2026-82028 · Severity: high · CVSS 8.8 · Published 2026-09-14

Executive brief

Magistrala is an open-source IoT platform that provides data reading and management services. A SQL injection vulnerability in its reader APIs allows authenticated users to inject arbitrary SQL commands, enabling attackers to extract sensitive database information (including password hashes), read/write files, and execute code with superuser privileges—effectively gaining full control of the underlying PostgreSQL database and the operating system.

Technical details

The vulnerability is a SQL injection flaw in the timescale-reader and postgres-reader HTTP API services, where the format query parameter is interpolated directly into a FROM clause without parameterization or identifier quoting. Authenticated attackers can supply malicious format values to inject arbitrary SQL subqueries. The attack is preconditioned on having a valid (self-registered) account, and leverages the default PostgreSQL role configuration where injected SQL executes at superuser privilege. Successful exploitation allows cross-tenant database reads, extraction of pg_shadow password hashes, arbitrary file read/write operations, and remote code execution as the postgres OS user via loading attacker-supplied shared objects. The fix was merged in PR #3581 (commit aac9461) on August 19, 2026, which implements format validation to reject non-bare SQL identifiers.

Affected products

  • Magistrala Magistrala before 1.0.0

Timeline

  • 2026-09-14: disclosed: CVE-2026-82028 published
  • 2026-08-19: patched: Fix merged in PR #3581 (commit aac9461)

References