---
id: CVE-2026-19354
title: >-
  A vulnerability was found in lock-upme OPMS up to
  831440f37a92c1568f2e071d5233bc873a9d8b09
summary: >-
  A vulnerability was found in lock-upme OPMS up to
  831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown
  function of the file controllers/messages/message.go of the component IN
  Clause Handler. Performing a manipula…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19354'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-19354'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/865991'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387208'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387208/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-09T18:34:01.081Z'
epss: 0.00316
epssPercentile: 0.21931
---

## Overview

A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
