CVE-2026-3021
Awaiting Analysis Awaiting Analysis - Queue

NoSQL Injection in Wakyma Endpoint Exposes Employee Data

Vulnerability report for CVE-2026-3021, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-03-16

Last updated on: 2026-03-20

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/centro/equipo/empleado'. This vulnerability could allow an authenticated user to alter a GET request to the affected endpoint for the purpose of injecting special NoSQL commands. This would lead to the enumeration of sensitive employee data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-03-16
Last Modified
2026-03-20
Generated
2026-07-28
AI Q&A
2026-03-16
EPSS Evaluated
2026-07-26
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wakyma wakyma *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a non-relational SQL injection (NoSQLi) found in the Wakyma web application, specifically at the endpoint 'vets.wakyma.com/centro/equipo/empleado'.

An authenticated user can manipulate a GET request to this endpoint by injecting special NoSQL commands.

This injection allows the attacker to enumerate sensitive employee data.

Detection Guidance

I don't know

Impact Analysis

The vulnerability could allow an authenticated user to access and enumerate sensitive employee data by injecting NoSQL commands into a GET request.

This unauthorized access to sensitive information could lead to data breaches, privacy violations, and potential misuse of employee data.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3021. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart