
Exploit code for CVE-2026-42096 and CVE-2026-42097 allowing for arbitrary SQL command execution without authentication.
Exploit code for executing arbitrary SQL command in Sparx PCS server without authentication.
NOTE: the key is NOT correct to prevent s|<rIpt kIddi3 from easy hacking ;-)
Full writeup: https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html
Credits: br0x (https://sploit.tech/) Team: Efigo (https://efigo.pl)