CVE-2026-8462
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
- Published Sep 16, 2026
- CVSS 8.9 high
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available