Executive Summary
Internal security review identified a vulnerability in Netwrix Access Analyzer 26. Insufficient authorization controls may permit an authenticated user to execute SQL queries against the underlying database beyond their intended privileges, potentially resulting in unauthorized access to, modification of, or loss of sensitive data stored within the application.
While Netwrix is unaware of any current exploitation of this vulnerability, all Netwrix Access Analyzer customers are advised to apply the available update immediately.
Vulnerability
| Title | Affected Component | Affected Versions | CVSS 4.0 Score | CVSS 3.1 Score (Base / Temporal) | Description |
|---|---|---|---|---|---|
| Authorization Bypass Through User-Controlled Key | Netwrix Access Analyzer | < 1.0.11 | 8.7 | 8.8 / 7.9 | Modification of references permits an authenticated user to execute SQL against the underlying database beyond its intended scope. |
Exploitability
Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.
| Title | Publicly known? | Exploit available? | Actively exploited? |
|---|---|---|---|
| Authorization Bypass Through User-Controlled Key | No | No | No |
Solution
Netwrix Access Analyzer automatically updates to the remediated version as soon as it becomes available. To confirm the fix has been applied, run dspmctl version and verify the reported version is 1.0.11 or later. Additional information can be found in the Netwrix Access Analyzer documentation.
Please contact the Netwrix technical support team should you need assistance.
Official Fixes
Updated software has been released containing an official fix for the vulnerability as indicated in the table below.
| Product | Release Version |
|---|---|
| Netwrix Access Analyzer | 1.0.11 |
FAQ
-
How do I confirm that the fix has been applied?
Run
dspmctl versionfrom the command line. If the reported version is 1.0.11 or later, the fix has been successfully applied. -
Are there any configuration changes required after updating?
No additional configuration changes are required. The fix is automatically applied upon updating to the remediated version.
Revisions
Updates to this advisory may be made as necessary. Information about each change will be published in the table below.
| Revision | Date | Description |
|---|---|---|
| 1 | 2026-06-11T12:00:00Z | First published |
Disclaimer
The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.