CVE-2026-52472

Wgcloud · Wgcloud

A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.

Executive summary

A critical SQL injection vulnerability in Wgcloud 3.6.4 poses a severe risk of total system compromise and unauthorized privilege escalation by unauthenticated remote attackers.

Vulnerability

The software contains a SQL injection flaw within the PortInfoMapper.xml file that permits unauthenticated remote attackers to execute arbitrary database commands. This vulnerability allows for unauthorized privilege escalation and full control over the database backend.

Business impact

The CVSS score of 9.8 reflects the critical nature of this flaw, as it allows for complete system compromise without requiring user interaction or prior authentication. Successful exploitation may result in the exfiltration of sensitive data, complete loss of database integrity, and total service disruption, leading to significant financial and reputational damage.

Remediation

Immediate Action: Since a specific patch version is currently unavailable, users should isolate affected Wgcloud instances from public networks and restrict access to authorized management segments only.

Proactive Monitoring: Security teams should monitor database logs for suspicious SQL syntax, unexpected query patterns, or unauthorized administrative privilege escalation attempts originating from the application service.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block SQL injection payloads targeting the application, which may provide a temporary virtual patch against exploitation.

Exploitation status

Public Exploit Available: Yes — a proof-of-concept exists as referenced in the provided GitHub repository.

Analyst recommendation

Given the critical severity and the existence of a proof-of-concept, this vulnerability represents an urgent security risk. Organizations must prioritize restricting network access to the affected Wgcloud component and remain alert for vendor updates to apply the necessary patches as soon as they become available.