SQL injection in Gaia - CVE-2026-48134
Published: May 28, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote user to manipulate stored DLP/UserCheck incident information and cause a denial of service.
The vulnerability exists due to SQL injection in the UserCheck Web Portal UserChoice flow when handling input on the UserCheck Ask page. A remote user can submit crafted input to manipulate stored DLP/UserCheck incident information and cause a denial of service.
Only systems with DLP active are vulnerable, and exploitation requires access to the UserCheck Ask page.