Vulnerability Details CVE-2026-34191
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 29.0%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2026-34191
-
cpe:2.3:a:apache:apr-util:1.6.0
-
cpe:2.3:a:apache:apr-util:1.6.1