CVE-2026-72565: Tencent Apijson

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator.

Affected products

  • Tencent Apijson: from 7.1.0, up to and including 8.1.8

Published 2026-08-10. Last modified 2026-08-28.