CVE-2026-72565: Tencent Apijson
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.
Affected products
- Tencent Apijson: from 7.1.0, up to and including 8.1.8
Published 2026-08-10. Last modified 2026-08-28.