CVE-2026-42100

HIGH

CVSS v3.1: 7.5 · EPSS: 0.0005 (14.8 percentile)

NetworkNo privilegesNo user interaction

Source data as of:

At a glance

Severity
HIGH
CVSS
7.5 v3.1 · NVD
EPSS
0.0005 (14.8 percentile) · FIRST.org
CISA KEV
No
Attack conditions (CVSS vector)
NetworkNo privilegesNo user interaction · Source: NVD Vector
Affected vendors
sparxsystems
Published
2026-05-19 · Modified: 2026-06-02

CVSS / EPSS / KEV

CVSS v3.1 7.5 / 10 HIGH Source: NVD
CVSS v4.0 7.1 / 10 HIGH Source: NVD
EPSS 0.0005 14.8 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.  The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

Record details

CVE ID
CVE-2026-42100
CVSS (v3.1)
7.5 (HIGH)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability subscore
3.9
Impact subscore
3.6
EPSS
0.0005 (14.8 percentile) — 2026-06-03
CISA KEV
No
Weakness (CWE)
CWE-228
Affected vendors
sparxsystems
Affected configurations (CPE)
1
Published
2026-05-19
Modified
2026-06-02
Status
Analyzed

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.