Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-4530: SQL injection in Aix-DB text2sql agent terminology retriever

A SQL injection flaw (CVE-2026-4530) was disclosed in apconw Aix-DB up to version 1.2.3, affecting the agent/text2sql/rag/terminology_retriever.py component via manipulation of the Description argument. The attack requires local access, a public exploit has been released, and the vendor did not respond to the disclosure.

Disclosed 22 March 2026 · Record updated 13 September 2026

Impact

SQL injection can be triggered through the text2sql RAG terminology retriever; exploit code is publicly available, though exploitation requires local access.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-4530