CVE-2026-8462: Openmeter
High severity, CVSS 8.9. EPSS: 0.5% chance of exploitation in the next 30 days.
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
Affected products
- Openmeter Openmeter
Published 2026-09-16. Last modified 2026-09-18.