CVE-2026-50813

EUVD-2026-42502
An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.48%
Debian logo
Debian Releases
Debian Product
Codename
sqlite3
bookworm
postponed
bullseye
postponed
bullseye (security)
vulnerable
forky
3.53.4-2
fixed
sid
3.53.4-2
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sqlite
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
dne
resolute
dne
trusty
needs-triage
xenial
needs-triage
sqlite3
bionic
needs-triage
focal
needs-triage
jammy
Fixed 3.37.2-2ubuntu0.7
released
noble
Fixed 3.45.1-1ubuntu2.7
released
questing
ignored
resolute
Fixed 3.46.1-9ubuntu0.2
released
trusty
needs-triage
xenial
needs-triage