CVE-2026-49498 - Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username
CVE ID :CVE-2026-49498 Published : June 10, 2026, 2:16 p.m. | 59 minutes ago Description :Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabase that fails to escape double quotes in usernames interpolated into ALTER ROLE...