A vulnerability was identified in java110 MicroCommunity up to 2.0. (CVE-2026-96803)
A SQL injection vulnerability exists in java110 MicroCommunity up to version 2.0 in the fallBack API Endpoint, specifically in the QueryServiceSMOImpl.fallBack function of BusinessApi.java. This vulnerability allows remote attackers to manipulate the fallBackSql argument, potentially leading to unauthorized data access or modification. The vulnerability has a CVSS score of 7.3, indicating a medium severity level. The project has been informed but has not yet responded or issued a patch. Public exploit code is available, but no known exploitation in the wild has been reported.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-96803 affects java110 MicroCommunity versions up to 2.0. It resides in the fallBack API Endpoint's QueryServiceSMOImpl.fallBack function within BusinessApi.java. The flaw allows remote attackers to perform SQL injection by manipulating the fallBackSql argument. This can lead to unauthorized disclosure, modification, or destruction of data. The vulnerability is remotely exploitable without authentication and has a CVSS 3.1 score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). The project was notified early but has not yet provided a fix or mitigation. Public exploit code exists, increasing the risk of exploitation.
Potential Impact
Successful exploitation of this vulnerability can lead to unauthorized reading, modification, or deletion of data in the affected system due to SQL injection. The vulnerability is remotely exploitable without any privileges or user interaction, which increases its risk. However, no confirmed active exploitation in the wild has been reported to date.
Mitigation Recommendations
No official fix or patch has been released by the vendor as of the current information. Users should monitor the vendor's communications for updates. In the meantime, consider implementing application-level input validation and SQL query parameterization as temporary mitigations to reduce the risk of SQL injection. Avoid exposing the vulnerable API endpoint to untrusted networks if possible.
A vulnerability was identified in java110 MicroCommunity up to 2.0. (CVE-2026-96803)
Description
A SQL injection vulnerability exists in java110 MicroCommunity up to version 2.0 in the fallBack API Endpoint, specifically in the QueryServiceSMOImpl.fallBack function of BusinessApi.java. This vulnerability allows remote attackers to manipulate the fallBackSql argument, potentially leading to unauthorized data access or modification. The vulnerability has a CVSS score of 7.3, indicating a medium severity level. The project has been informed but has not yet responded or issued a patch. Public exploit code is available, but no known exploitation in the wild has been reported.
CVSS v3.1
Score 7.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-96803 affects java110 MicroCommunity versions up to 2.0. It resides in the fallBack API Endpoint's QueryServiceSMOImpl.fallBack function within BusinessApi.java. The flaw allows remote attackers to perform SQL injection by manipulating the fallBackSql argument. This can lead to unauthorized disclosure, modification, or destruction of data. The vulnerability is remotely exploitable without authentication and has a CVSS 3.1 score of 7.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). The project was notified early but has not yet provided a fix or mitigation. Public exploit code exists, increasing the risk of exploitation.
Potential Impact
Successful exploitation of this vulnerability can lead to unauthorized reading, modification, or deletion of data in the affected system due to SQL injection. The vulnerability is remotely exploitable without any privileges or user interaction, which increases its risk. However, no confirmed active exploitation in the wild has been reported to date.
Mitigation Recommendations
No official fix or patch has been released by the vendor as of the current information. Users should monitor the vendor's communications for updates. In the meantime, consider implementing application-level input validation and SQL query parameterization as temporary mitigations to reduce the risk of SQL injection. Avoid exposing the vulnerable API endpoint to untrusted networks if possible.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4mm4-mwxf-r2wr
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-96803"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab4be18f7a7c54106eee663
Added to database: 09/24/2026, 06:07:20 UTC
Last enriched: 09/24/2026, 06:12:26 UTC
Last updated: 09/24/2026, 18:47:33 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.