CVE-2026-82526 | SciPhi-AI R2R up to 3.6.6 Vector Index Creation index name sql injection

SecurityVulns

A vulnerability categorized as critical has been discovered in SciPhi-AI R2R up to 3.6.6. Impacted is an unknown function of the component Vector Index Creation. Such manipulation of the argument index name leads to sql injection.

This vulnerability is documented as CVE-2026-82526. The attack can be executed remotely. There is not any exploit available.

A patch should be applied to remediate this issue.VulDB Recent EntriesRead More