CVE-2026-34191
published 2026-08-06CVE-2026-34191: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle…
PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.35%
27.7th percentile
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | 1.6.0 – 1.6.3 | — |
| apache_software_foundation | apache_portable_runtime_utility | 1.6.0 – 1.6.3 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
ghsa_unreviewed·2026-08-06
CVE-2026-34191 [CRITICAL] CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Red Hat
apr-util: Apache Portable Runtime Utility: SQL Injection via apr_dbd_oracle
vendor_redhat·2026-08-06·CVSS 9.1
CVE-2026-34191 [CRITICAL] CWE-89 apr-util: Apache Portable Runtime Utility: SQL Injection via apr_dbd_oracle
apr-util: Apache Portable Runtime Utility: SQL Injection via apr_dbd_oracle
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
A flaw was found in Apache Portable Runtime Utility. This vulnerability, known as SQL Injection, occurs in the `apr_dbd_oracle` provider. A remote attacker could exploit this by injecting malicious SQL commands, potentially leading to unauthorized access, modification, or deletion of data within the database.
Statement: Red Hat products are not affected by this flaw. The vulnerability is specific to the apr_dbd_oracle database driver module in the Apache Portable Runtime Utili
No detection rules found.
No public exploits indexed.
2026-08-06
Published