No advisories yet.
Solution
Wakyma has fixed the vulnerability in the continuous integration deployed in production since February 19, 2026.
Workaround
No workaround given by the vendor.
Mon, 16 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wakyma.com/hospitalization/generate-hospitalization-summary'. This vulnerability could allow an authenticated user to alter a POST request to the affected endpoint for the purpose of injecting special NoSQL commands, resulting in the attacker being able to obtain customer reports. | |
| Title | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma application web | |
| First Time appeared |
Wakyma
Wakyma wakyma Application Web |
|
| Weaknesses | CWE-943 | |
| CPEs | cpe:2.3:a:wakyma:wakyma_application_web:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Wakyma
Wakyma wakyma Application Web |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-16T15:26:40.413Z
Reserved: 2026-02-23T13:43:55.333Z
Link: CVE-2026-3022
Updated: 2026-03-16T15:26:36.730Z
Status : Awaiting Analysis
Published: 2026-03-16T14:19:45.493
Modified: 2026-03-16T14:53:07.390
Link: CVE-2026-3022
No data.
OpenCVE Enrichment
No data.