Skip to content
CVE-2026-52887 - Exploits & Severity

CVE-2026-52887 - Exploits & Severity

Feedly • July 16, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)

NocoBase Notification component allows remote attackers to manipulate the `latestMsgReceiveTimestamp` argument and trigger SQL injection via `Sequelize.literal` in the `/api/myInAppChannels` endpoint.

An unauthenticated attacker over the network can execute arbitrary SQL queries against the database by injecting malicious payloads through the `latestMsgReceiveTimestamp` parameter, potentially allowing them to read, modify, or delete database contents.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Not specified in provided data

Upgrade NocoBase to a version newer than 2.0.60. Implement input validation and parameterized queries to prevent SQL injection. Apply web application firewall rules to detect and block SQL injection attempts targeting the `/api/myInAppChannels` endpoint. Consider restricting access to the notification API endpoint if not widely required by end users.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

NVD published the first details for CVE-2026-52887

Feedly found the first article mentioning CVE-2026-52887 . See article

A CVSS base score of 10 has been assigned.

CVE-2026-52887 - Exploits & Severity - Feedly

CVE-2026-52887 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notificati…

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (1)