Skip to content

CVE-2026-69240

CVE

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 4, 2026
Last Seen
August 4, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

CVE-2026-69240 is a critical SQL injection vulnerability affecting Sequelize ORM when configured for Oracle databases. The flaw, rated 9.8 on the CVSS scale, allows attackers to inject arbitrary SQL expressions through specially crafted input starting with 'TO_TIMESTAMP' or 'TO_DATE'. The escape fun...

Public Exploits

Checking GitHub for proof-of-concept code…