Five flaws found in Sparx Systems software
CERT Polska coordinated disclosure of five vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect, including an unauthenticated SQL injection path leading to remote code execution.
CERT Polska, working with researcher Blazej Adamczyk (br0x) of Efigo, coordinated disclosure of five vulnerabilities affecting Sparx Systems' Pro Cloud Server (version 6.1 build 167 and below) and Enterprise Architect (version 17.1 and below). The issues range from broken access control allowing low-privileged users to run arbitrary SQL queries, to an authentication bypass that permits unauthenticated SQL execution by omitting the 'model' query parameter and embedding it in a binary POST blob instead.
The most severe issue, CVE-2026-42099, is a race condition in the /data_api/dl_internal_artifact.php endpoint that lets an attacker with repository access plant a malicious PHP file and execute it before it is deleted, resulting in remote code execution. A separate flaw (CVE-2026-42098) allows an authenticated user to manipulate the Enterprise Architect client (e.g., via a debugger) to impersonate any user, including administrators, and make arbitrary repository changes. A fifth vulnerability (CVE-2026-42100) enables denial of service by crashing the Pro Cloud Server via a malformed SQL query.
The vendor was notified early but did not respond with vulnerability details or confirm the affected version range beyond what researchers tested, so other versions may also be vulnerable. No public exploitation has been reported; this is a coordinated disclosure advisory rather than an active-exploitation alert.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-42096
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free