CVE-2026-32622: SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permi...

Added to the CISA Known Exploited Vulnerabilities catalog on 19 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology,...

Required action: Review and patch if applicable to your AI infrastructure.