CVE•Published 2026-05-19•Modified 2026-06-02•1 article on news•7 live references•NVD data
CVE-2026-42096Sparxsystems · Pro_cloud_server
Vulnerability data via NVD (ingested)
CVSS v3.1
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
—
Weaknesses (CWE)
Description
Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Timeline
Published 2026-05-19
Modified 2026-06-02
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-42096Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Sparxsystems Pro Cloud Server"All exposed Sparxsystems Pro Cloud Server instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Pro Cloud Server"HTTP body or banner mentions "Pro Cloud Server" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-42096Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-42096Censys host search filtered to this CVE id.
grep.app
CVE-2026-42096Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-42096GitHub code search for direct mentions.
Google dork
"CVE-2026-42096" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.