SB2026052524 - SQL injection in Mautic



SB2026052524 - SQL injection in Mautic

Published: May 25, 2026

Security Bulletin ID SB2026052524
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) SQL injection (CVE-ID: CVE-2026-3105)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in the Contact Activity API endpoint when processing the sort direction parameter in requests for the contact activity timeline. A remote user can send a specially crafted API request to execute arbitrary SQL commands.


Remediation

Install update from vendor's website.