CVE-2026-50813: SQL Injection
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SQLiteto a version that resolves this vulnerability.Fixed in Fossil check-in 869a51ae84df
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50813?
The severity of CVE-2026-50813 is classified as medium with a score of 6.1.
How do I fix CVE-2026-50813?
To fix CVE-2026-50813, update to a version of SQLite that includes the patch from Fossil check-in 869a51ae84df or later.
What type of vulnerability is CVE-2026-50813?
CVE-2026-50813 is classified as an SQL Injection vulnerability.
What kind of information can be exposed by CVE-2026-50813?
CVE-2026-50813 allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path.
Is user interaction required to exploit CVE-2026-50813?
Yes, user interaction is required as indicated by the user interaction mitigation in CVE-2026-50813.