CVE-2026-15804 HIGH

CVE-2026-15804: MetaGuru|HCM - SQL Injection

Vendor Metaguru
Product HCM
Weakness CWE-89 · SQLi
Published July 15, 2026
Last update July 15, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, thereby compromising the confidentiality, integrity, and availability of database data.

Key dates

02Disclosure timeline

July 15, 2026 CVE published

Related vulnerabilities

04Related CVE