
PEACH
Un cadre d’isolation des locataires
CVE-2026-34191 is a SQL Injection vulnerability (CWE-89) in Apache Portable Runtime Utility (APR-util) affecting the apr_dbd_oracle database provider. It affects APR-util versions 1.6.0 through 1.6.3 and was publicly disclosed on August 6, 2026, with a patch released the same day. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical), reflecting its network-exploitable, unauthenticated attack vector with high confidentiality and integrity impact (Apache Advisory, GitHub Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and resides specifically in the apr_dbd_oracle provider of Apache Portable Runtime Utility. The apr_dbd interface is a database abstraction layer used by Apache HTTP Server and other APR-based applications; the Oracle backend fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL commands, enabling injection of arbitrary SQL. Exploitation requires no authentication and no user interaction, and can be performed remotely over the network with low attack complexity (Apache Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend Oracle database, resulting in high confidentiality impact (unauthorized data read) and high integrity impact (data modification or deletion). Depending on the database account privileges, attackers may also be able to execute operating system commands via Oracle database features (e.g., DBMS_SCHEDULER or UTL_FILE), potentially enabling lateral movement beyond the database tier. Availability is not directly impacted according to the CVSS scoring, though data destruction is possible (Apache Advisory, GitHub Advisory).
As of the disclosure date (August 6, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, indicating that exploitation could be scripted at scale if a PoC becomes available. The EPSS score is currently 0.0, reflecting the early stage of the vulnerability's public lifecycle. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Apache Advisory, GitHub Advisory).
The Apache Software Foundation has released a fix for this vulnerability; users should upgrade Apache Portable Runtime Utility to a version beyond 1.6.3 as soon as possible. As interim mitigations, organizations should restrict network access to applications that use the apr_dbd_oracle provider, implement a web application firewall (WAF) with SQL injection detection rules, and enforce the principle of least privilege on Oracle database accounts used by APR-util to limit the blast radius of any exploitation. Additionally, implementing parameterized queries or input validation at the application layer provides defense-in-depth (Apache Advisory, GitHub Advisory).
The vulnerability was noted on the oss-security mailing list shortly after disclosure and received brief social media attention on Bluesky within hours of publication. Community reaction has been measured given the absence of a public PoC and the relatively niche attack surface (Oracle-backed APR-util deployments). No significant vendor statements beyond the Apache advisory or notable researcher deep-dives have been published as of the disclosure date (oss-sec).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."