External risk intelligence

Anyquery SQL Injection Allows Arbitrary File Write and Denial of Service

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-50006

Anyquery acts as a SQL query engine providing a MySQL-compatible server port. While it can be configured to listen on a network, it is typically used as a developer tool or utility for querying local or remote data sources rather than being a public-facing internet service by design. Its exposure depends heavily on the specific deployment context chosen by the user.

Path Traversal

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a vulnerability in Anyquery, a SQL query engine, that could allow an unauthenticated remote attacker to create or overwrite files on the server. While the primary impact is loss of filesystem integrity and denial of service, remote code execution is a possibility under certain conditions. The main concern is confirming if Anyquery is in use and if it is exposed to external networks.

  • Unauthenticated attackers can write files on the server.
  • Allows system compromise and denial of service.
  • Confirm Anyquery use and network exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by connecting to the Anyquery server's MySQL-compatible port over the network. Because the server forwards unauthenticated SQL queries to SQLite without restricting filesystem targets, the attacker can instruct the server to create a database file in any location writable by the Anyquery process. This enables the attacker to add controlled data to the new file, potentially leading to arbitrary file creation or overwrite, denial of service, and in some scenarios, remote code execution.

  • No authentication required for access.
  • Attacker controls SQL queries to the server.
  • Filesystem integrity loss and DoS risk.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could exploit this vulnerability by sending unauthenticated SQL queries to the Anyquery server. When supported by the advisory, this could allow the attacker to write arbitrary files to the server's filesystem, potentially leading to a denial of service or even remote code execution if another service interprets the created file or the process has a privileged writable target.

  • Filesystem integrity loss and denial of service.
  • Attacker writes files via SQL injection.
  • Arbitrary file creation or overwrite.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for the Anyquery server, likely application or platform owners, must first identify all instances of this SQL query engine. Confirming network reachability and business criticality for each instance will inform prioritization. The next step is to locate the accountable owner and plan remediation, considering any external dependencies or potential impact on filesystem integrity.

  • Identify Anyquery instances and owners.
  • Verify network exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Anyquery and how is it used?

Anyquery is an SQL query engine designed to bridge various data sources by using SQLite as its core processing engine. Developers typically use it as a utility to run SQL queries against diverse datasets, including local files or remote databases, through a MySQL-compatible interface.

What kind of vulnerability is CVE-2026-50006?

This vulnerability is an improper control of file system paths, categorized under weaknesses like CWE-22 (Path Traversal) and CWE-284 (Improper Access Control). In plain terms, the server fails to restrict where the database engine can write files, allowing unauthorized commands to target arbitrary locations on the system.

How does an attacker trigger this issue?

An attacker exploits this by connecting to the Anyquery MySQL-compatible port and sending specially crafted SQL commands. The vulnerability is triggered when these unauthenticated queries direct the engine to use the ATTACH DATABASE command against a restricted path. Simply querying standard data sources without triggering file creation operations does not initiate this specific flaw.

Is my system at risk if Anyquery is running?

Risk depends heavily on your deployment, as Halo Surface Signal notes that Anyquery is often a developer utility rather than a public-facing service. If your instance is reachable from the internet, it faces a higher likelihood of external exploitation compared to those running in isolated or internal-only environments.

How should I address this CVE-2026-50006 vulnerability?

Prioritize identifying all active instances of Anyquery within your environment. Once located, verify if they are running version 0.4.5 or later. If you are on an older version, update the software immediately to apply the fix that restricts these insecure database file path operations.

References