Back cve.akaoma.com CVE-2026-69240 AKAOMA CVE VULNERABILITIES / 1h Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an app
9.8 /10 Critical Risk As a catastrophic security flaw, CVE-2026-69240 has severe implications, demanding immediate intervention.
As a catastrophic security flaw, CVE-2026-69240 has severe implications, demanding immediate intervention.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
