
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34191 is a SQL Injection vulnerability (CWE-89) in Apache Portable Runtime Utility (APR-util) affecting the apr_dbd_oracle database provider. It affects APR-util versions 1.6.0 through 1.6.3 and was publicly disclosed on August 6, 2026, with a patch released the same day. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical), reflecting its network-exploitable, unauthenticated attack vector with high confidentiality and integrity impact (Apache Advisory, GitHub Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and resides specifically in the apr_dbd_oracle provider of Apache Portable Runtime Utility. The apr_dbd interface is a database abstraction layer used by Apache HTTP Server and other APR-based applications; the Oracle backend fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL commands, enabling injection of arbitrary SQL. Exploitation requires no authentication and no user interaction, and can be performed remotely over the network with low attack complexity (Apache Advisory, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend Oracle database, resulting in high confidentiality impact (unauthorized data read) and high integrity impact (data modification or deletion). Depending on the database account privileges, attackers may also be able to execute operating system commands via Oracle database features (e.g., DBMS_SCHEDULER or UTL_FILE), potentially enabling lateral movement beyond the database tier. Availability is not directly impacted according to the CVSS scoring, though data destruction is possible (Apache Advisory, GitHub Advisory).
As of the disclosure date (August 6, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The NVD SSVC assessment classifies the vulnerability as automatable with total technical impact, indicating that exploitation could be scripted at scale if a PoC becomes available. The EPSS score is currently 0.0, reflecting the early stage of the vulnerability's public lifecycle. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Apache Advisory, GitHub Advisory).
The Apache Software Foundation has released a fix for this vulnerability; users should upgrade Apache Portable Runtime Utility to a version beyond 1.6.3 as soon as possible. As interim mitigations, organizations should restrict network access to applications that use the apr_dbd_oracle provider, implement a web application firewall (WAF) with SQL injection detection rules, and enforce the principle of least privilege on Oracle database accounts used by APR-util to limit the blast radius of any exploitation. Additionally, implementing parameterized queries or input validation at the application layer provides defense-in-depth (Apache Advisory, GitHub Advisory).
The vulnerability was noted on the oss-security mailing list shortly after disclosure and received brief social media attention on Bluesky within hours of publication. Community reaction has been measured given the absence of a public PoC and the relatively niche attack surface (Oracle-backed APR-util deployments). No significant vendor statements beyond the Apache advisory or notable researcher deep-dives have been published as of the disclosure date (oss-sec).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."