No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against other workspaces' memory databases to read, insert, or delete data. | |
| Title | Coze Studio through 0.5.1 Cross-Tenant Database Access via Workflow SQL Node | |
| First Time appeared |
Coze
Coze coze Studio |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:coze:coze_studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coze
Coze coze Studio |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T13:47:34.949Z
Reserved: 2026-09-16T19:31:52.771Z
Link: CVE-2026-92788
Updated: 2026-09-17T13:47:28.234Z
Status : Received
Published: 2026-09-16T21:17:28.180
Modified: 2026-09-17T14:17:56.200
Link: CVE-2026-92788
No data.
OpenCVE Enrichment
Updated: 2026-09-18T00:00:13Z