CVE-2026-3022
Awaiting Analysis Awaiting Analysis - Queue

NoSQL Injection in Wakyma Endpoint Exposes Customer Reports

Vulnerability report for CVE-2026-3022, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-03-16

Last updated on: 2026-03-19

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting special NoSQL commands, resulting in the attacker being able to obtain customer reports.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-03-16
Last Modified
2026-03-19
Generated
2026-07-26
AI Q&A
2026-03-16
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wakyma wakyma *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Non-relational SQL injection (NoSQLi) found in the Wakyma web application. It specifically affects the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. An authenticated user can manipulate a POST request to this endpoint by injecting special NoSQL commands.

As a result, the attacker can exploit this injection to obtain customer reports that they should not normally have access to.

Detection Guidance

I don't know

Impact Analysis

This vulnerability can allow an authenticated attacker to access sensitive customer reports by injecting malicious NoSQL commands into a POST request.

Such unauthorized access to confidential information can lead to data breaches, loss of customer trust, and potential financial and reputational damage.

Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-3022. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart