- Advisory: GHSA-r9rr-vpw9-p66x · CVE-2026-52764
- Severity: High · CWE-78
- Status: publicly disclosed and fixed. Reported by Pig-Tail through coordinated disclosure.
MSSQL inventory module executes OS commands with unsanitized database names and credential fields
Write-up only. No standalone runnable PoC is published for this finding here — refer to the linked advisory for full technical detail, affected range, and the fixed version.