What is CVE-2026-5587?
A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py of the component Refiner Agent. The manipulation leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Timeline
- 2026-04-05Published to the U.S. National Vulnerability Database (NVD)
- 2026-07-24NVD record last updated
Affected product
See advisory
Remediation Steps
- Update Apache HTTP Server to version 2.4.63 or later during next scheduled maintenance.
- Ensure mod_security or equivalent WAF rules are active as additional defense.
- No emergency action required.
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of March 2026 (March 14–20)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.