Back

MEDIUM

Kamaji: SQL injection via unescaped datastore identifiers in PostgreSQL/MySQL drivers

Published Jul 30, 2026

Description

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 30, 2026
Updated Jul 31, 2026
Reserved Jul 14, 2026

CISA Vulnrichment

Updated Jul 31, 2026

NVD

Status Deferred
Modified Sep 8, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 30, 2026
Updated Jul 31, 2026

GitHub

No data