cvedb.io
CVE-2026-42100
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-05-19T14:16:43.113 · Last modified 2026-06-17T10:47:26.070

Summary

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.  The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

Affected products

sparxsystems — pro_cloud_server

Does this affect you?

Add your gear to cvedb and we'll alert you only when sparxsystems ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.