Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus September 19, 2026

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.

| CVE | [CVE-2026-79752]( · [CVE.org]( |

| CWE | [CWE-89]( |

| CVSS | **Critical: 9.2** `CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N` |

| Product | [CakePHP]( |

| Affected | 5.2.x **through 5.2.13** (also 4.5.x Connection::func()->cast('body', $_GET['type']). FunctionsBuilder::cast setConjunction AS add literal dataType. CakePHP 5.2.13. Fixed 5.2.14.

- **Notes:** CVE-2026-79752 CWE-89 CakePHP 5.2.13. Witness POCWitness79752. Not WordPress.

- `FunctionsBuilder::cast splices type as literal`

- `notes.body POCWitness79752 in HTTP body`

POCWitness79752 in the HTTP body AND sql= line shows the injected fragment (not only CAST(body AS TEXT)).

- CAST AS TEXT only, no injection fragment in sql=

**Do this first:** Update **CakePHP** to **5.2.14** (or 5.3.7 / 5.1.9 / 4.6.5 / 4.5.12). Advisory: [GHSA-vjqc-q4mp-2rvf](

- Re-run `CVE-2026-79752-Abraxas-Labs.py` against the patched build: the mapped witness must **not** appear.

- Confirm the vendor advisory / changeset in the deployed tree (see references).

- Disable or isolate the affected component.

- Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).

Target **only** ` (or the loopback you bound). Do not point this script at the internet.

Success is the **witness** above in the response body. Generic 200 HTML is not it.

Loopback stack used to reproduce. Official images unless a `Dockerfile` in this folder builds from source.

- [`lab/docker-compose.yml`](lab/docker-compose.yml)

Bind the vulnerable product tree to Compose if the YAML mounts a local directory (plugin zip / source tag from the version table). Publish nothing except `127.0.0.1`.

- [CVE-2026-79752 · NVD](

- [CVE-2026-79752 · CVE.org](

- [github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0](

- [github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e](

- [github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676](

- [github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d](

- [github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45](

- [github.com/cakephp/cakephp/pull/19520](

- [github.com/cakephp/cakephp/pull/19528](

- [github.com/cakephp/cakephp/releases/tag/4.5.12](

- [github.com/cakephp/cakephp/releases/tag/4.6.5](

- [github.com/cakephp/cakephp/releases/tag/5.1.9](

- [github.com/cakephp/cakephp/releases/tag/5.2.14](

- [github.com/cakephp/cakephp/releases/tag/5.3.7](

- [github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf](

- [github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79752.json](

- [nvd.nist.gov/vuln/detail/CVE-2026-79752](

- [github.com/advisories/GHSA-vjqc-q4mp-2rvf](

- [github.com/cakephp/cakephp/releases/tag/5.1.8](

- Abraxas Labs: [abraxaslabs.tech]( · [github.com/abraxas]( · [@abraxas_null](

- input: `

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.

- cakephp cakephp = 4.6.0, = 5.0.0, = 5.2.0, = 5.3.0,