Skip to content

Hide Navigation Hide TOC

SQL Injection Stacked DML Privilege Abuse - ATR-2026-01603 (00bed1bf-46ad-5779-be72-f12cc890e93d)

Detects stacked SQL injection where a secondary DML statement (UPDATE, INSERT, GRANT) is appended after a semicolon to modify data or escalate database privileges. Unlike destructive DDL (DROP/TRUNCATE), stacked DML abuse silently alters records—e.g., updating order status to bypass payment checks, inserting unauthorized admin users, or granting elevated SQL permissions. This targets agents that pass ORDER/FILTER inputs into SQL-executing tools without parameterization.

Cluster A Galaxy A Cluster B Galaxy B Level
SQL Injection Stacked DML Privilege Abuse - ATR-2026-01603 (00bed1bf-46ad-5779-be72-f12cc890e93d) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1
SQL Injection Stacked DML Privilege Abuse - ATR-2026-01603 (00bed1bf-46ad-5779-be72-f12cc890e93d) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1