CVE-2026-8462EPSS p41.5%
CVE-2026-8462CVE-2026-8462
Description
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
Scoring
| EPSS | 0.51% probability of exploitation · percentile 41.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-18 |