CVE-2026-88402

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

Published 2026-09-21. Last modified 2026-09-22.