CVE-2026-8462

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.

  • Published Sep 16, 2026
  • CVSS 8.9 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-8462 at the National Vulnerability Database