CVE-2026-42100

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Cloud Server service to terminate unexpectedly.  The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sparxsystems:pro_cloud_server:*:*:*:*:*:*:*:*

History

02 Jun 2026, 14:19

Type Values Removed Values Added
CPE cpe:2.3:a:sparxsystems:pro_cloud_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Sparxsystems pro Cloud Server
Sparxsystems
References () https://cert.pl/en/posts/2026/05/CVE-2026-42096 - () https://cert.pl/en/posts/2026/05/CVE-2026-42096 - Third Party Advisory
References () https://efigo.pl/blog/CVE-2026-42096/ - () https://efigo.pl/blog/CVE-2026-42096/ - Third Party Advisory
References () https://sparxsystems.com/products/procloudserver/ - () https://sparxsystems.com/products/procloudserver/ - Product
References () https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html - () https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html - Exploit, Third Party Advisory

19 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 14:16

Updated : 2026-06-02 14:19


NVD link : CVE-2026-42100

Mitre link : CVE-2026-42100

CVE.ORG link : CVE-2026-42100


JSON object : View

Products Affected

sparxsystems

  • pro_cloud_server
CWE
CWE-228

Improper Handling of Syntactically Invalid Structure