SonarSource SonarQube Authorization API Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability has been identified in the authorizations/group-memberships API endpoint of SonarSource SonarQube versions 10.4 through 10.5 prior to 10.6. This vulnerability allows users with the administrator role to inject SQL commands that are not visible but can be executed by the database.

Impact

Exploitation of this vulnerability allows for blind SQL injection, where an attacker can manipulate SQL queries executed by the application, potentially leading to unauthorized data access or modification.

Added: Jun 22, 2026, 10:23 AM
Updated: Jun 22, 2026, 10:23 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.