Critical severity9.8NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026
CVE-2026-50890
CVE-2026-50890
Description
Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: = 4.6.0
- Range: = 4.6.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.