CVE-2026-38467: n/a
Description
CVE-2026-38467 is a SQL injection vulnerability in the tags manager component of GazellePW (GazellePosterWall). It allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands by sending crafted POST requests to tools.php with specific tagid or type parameters. The vulnerability has a CVSS score of 5.4, indicating a medium severity level. No patch or remediation information is currently provided.
CVSS v3.1
Score 5.4medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability exists in GazellePW's tags manager, specifically in the handling of the tagid or type parameters in POST requests to tools.php?action=manage_tags. Authenticated users with users_mod privileges can exploit this SQL injection flaw to execute arbitrary SQL commands remotely. The CVSS 3.1 vector indicates the attack requires network access, low attack complexity, privileges, and no user interaction, with limited confidentiality and integrity impact and no availability impact.
Potential Impact
An attacker with users_mod privileges can leverage this vulnerability to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification within the database. The impact is limited to confidentiality and integrity, with no direct availability impact reported. The vulnerability requires authenticated access with specific privileges, reducing the attack surface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict users_mod privileges to trusted users only and monitor for suspicious activity related to tag management. Avoid exposing the vulnerable endpoint to untrusted networks if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-24pg-74pv-r836
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-38467"]
- State
- PUBLISHED
Threat ID: 6a8efff5acd9273b4908ca7b
Added to database: 08/26/2026, 15:02:13 UTC
Last enriched: 09/10/2026, 10:40:21 UTC
Last updated: 10/09/2026, 06:48:16 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.