Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries.
SMG 10.9.1
SMG is not affected by CVE-2026-35194 as the vulnerability is for Apache Flink, which is not used or installed with SMG.