CVE-2026-48528 | NCEAS Metacat up to 3.4.0 Rest Api Endpoint web.xml nodeId sql injection

SecurityVulns

A vulnerability classified as critical was found in NCEAS Metacat up to 3.4.0. This affects an unknown function of the file web.xml of the component Rest Api Endpoint. Such manipulation of the argument nodeId leads to sql injection.

This vulnerability is listed as CVE-2026-48528. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More