Report: CVE-2026-41457 - OwnTone Server < 29.1 SQL Injection via query and filter Parameters
CVE ID :CVE-2026-41457 Published : April 22, 2026, 1:46 a.m. | 1 hour, 12 minutes ago Description :OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= parameters for integer-mapped DAAP fields. Attackers can exploit insufficient sanitization of these parameters to bypass filters and gain unauthorized access to media library data. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...