Input validation error in Sparx Pro Cloud Server - CVE-2026-42100
Published: May 27, 2026
Sparx Pro Cloud Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the /SparxCloudLink.sseap endpoint when parsing SQL queries containing an unterminated escape sequence. A remote attacker can send a specially crafted SQL query to cause a denial of service.
The service terminates unexpectedly when an escape sequence starts with an opening curly brace without a matching closing brace.