Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-0603 — Hibernate ORM Second-Order SQL Injection | Kitploit
Ferramentas/GitHubGitHub/eqstlab/cve-2026-0603
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationDatabase Security
GitHubeqstlab/cve-2026-0603

CVE-2026-0603

Hibernate ORM Second-Order SQL Injection

Ver Repositório
1há 11 diasAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

CVE-2026-0603 Hibernate ORM Injection / Second-Order SQL Injection

★ CVE-2026-0603 Hibernate SQL Injection PoC ★

https://github.com/user-attachments/assets/2e7c3a89-e26f-48cd-af0b-8b82d32ce71f


Overview

CVE-2026-0603 is a Second-Order SQL Injection vulnerability in Hibernate ORM, a widely used Java ORM framework.
When a user-supplied string primary key containing a malicious SQL payload is used in a bulk DELETE or UPDATE operation, Hibernate inserts the value directly into the WHERE clause without sanitization, causing unintended mass deletion or modification of database records.


Affected Versions

Baixar ferramenta
CategoryVersion
VulnerableHibernate ORM 5.2.8 ≤ version ≤ 5.6.15
PatchedNo official patch (5.6.x EOL)

Impact

  • Mass deletion of records across multiple tables
  • Mass modification of records across multiple tables
  • Potential exfiltration of sensitive data from the database

Environment

root@kitploit:~
docker build -t cve-2026-0603-hibernate-vuln .
docker run --rm -it -p 8080:8080 --name hibernate-vuln cve-2026-0603-hibernate-vuln

PoC

After starting the vulnerable environment, follow the steps below to reproduce the attack.

Step 1. Register with a malicious username

root@kitploit:~
username: ' or '1' = '1

Step 2. Trigger update or delete

Click the update or delete button on the registered account.

Step 3. Confirm all user data is affected

Verify that the DELETE or UPDATE query was applied to all rows, not just the registered account. For DELETE, all records across both tables are removed. For UPDATE, all records are modified with the attacker-supplied values.


Mitigation

  • Remove the InlineIdsOrClauseBulkIdStrategy setting from application.yml
  • If InlineIdsOrClauseBulkIdStrategy must be used, apply strict whitelist-based input validation on any user-supplied primary key values to reject SQL control characters

Analysis

  • KR: https://www.skshieldus.com/security-insights/reports/eqst-orm-injection-explained
  • EN: https://www.skshieldus.com/en/report?tab=eqst