CVE-2025-27378

Published Jan 22, 2026

Last updated 4 months ago

Overview

Description
AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to inject and execute arbitrary SQL queries.
Source
4760f414-e1ae-4ff1-bdad-c7a9c3538b79
NVD status
Analyzed
Products
on-prem_enterprise_server

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

4760f414-e1ae-4ff1-bdad-c7a9c3538b79
CWE-20

Social media

Hype score
Not currently trending
  1. CVE-2025-27378 (CVSS:8.6, HIGH) is Awaiting Analysis. AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic f..https://t.co/5O6EHWemWB #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    27 Jan 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-27378 - AES SQL injection via inactive config preventing latest SQL parsing logic Check: grep -r "sql.parsing" /path/to/aes/config/ Source: https://t.co/cl4U9v0Ens

    @lsof

    22 Jan 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-27378 SQL Injection in AES Due to Inactive Configuration Bypass https://t.co/ZlznVjJVIQ Vulnerability Notification: https://t.co/xhLrNnfyrO

    @VulmonFeeds

    22 Jan 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-27378 AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is … https://t.co/tCHvEuNyRf

    @CVEnew

    22 Jan 2026

    159 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-27378: HIGH] Avoid SQL injection vulnerability in AES by activating latest SQL parsing logic in the configuration to prevent crafted input from being mishandled and exploited by attackers. #cyberse...#cve,CVE-2025-27378,#cybersecurity https://t.co/jTHbO8QJV0 https://t.c

    @CveFindCom

    22 Jan 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🟠 CVE-2025-27378 - High AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted inpu... https://t.co/Eu9NRnTxP9 https://t.co/CxfEuGf20p

    @TheHackerWire

    22 Jan 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.