---
id: CVE-2026-6093
title: >-
  Corteza contains a SQL injection vulnerability in its Microsoft SQL Server
  (MSSQL) backend when filtering Compose records by the meta field.This issue
  affects corteza: 2024.9.8.
summary: >-
  Corteza contains a SQL injection vulnerability in its Microsoft SQL Server
  (MSSQL) backend when filtering Compose records by the meta field.This issue
  affects corteza: 2024.9.8.
severity: medium
cvss: 6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-89
vendor: cortezaproject
product: corteza
affected:
  - corteza 2024.9.8
published: '2026-05-11'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T22:17:01.430'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6093'
references:
  - url: 'https://fluidattacks.com/es/advisories/motley'
    label: help@fluidattacks.com
  - url: 'https://github.com/cortezaproject/corteza'
    label: help@fluidattacks.com
  - url: >-
      https://github.com/cortezaproject/corteza/commit/64b58b9d7324e77248bacd183fb994ff338091ec
    label: help@fluidattacks.com
  - url: 'https://fluidattacks.com/es/advisories/motley'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-11T19:26:49.064495Z'
cvssSource: cna
epss: 0.00358
epssPercentile: 0.26788
ingestedAt: '2026-09-24T22:54:36.878Z'
---

## Overview

Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
