Skip to content
Critical SQL Injection Vulnerabilities in CakePHP Disclosed

Critical SQL Injection Vulnerabilities in CakePHP Disclosed

First seen 19 Sep 2026, 22:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 00:24 UTC
  • CVE-2026-79752 and CVE-2026-77635 are critical SQL injection vulnerabilities in CakePHP.
  • Both vulnerabilities have a CVSS score of 9.2, indicating significant risk.
  • Users must upgrade to the latest versions to mitigate these vulnerabilities.

Two critical SQL injection vulnerabilities affecting CakePHP have been disclosed. CVE-2026-79752 allows SQL injection through user-controlled parameters in FunctionsBuilder prior to versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7. CVE-2026-77635 affects FunctionsBuilder::jsonValue() with PostgresDriver, also allowing SQL injection when user-controlled data is supplied to the jsonPath parameter, impacting versions prior to 5.1.10, 5.2.15, and 5.3.7. Both vulnerabilities have a CVSS score of 9.2, indicating critical severity. The vulnerabilities can lead to confidentiality, integrity, and availability impacts based on database connection privileges. Users are advised to update to the fixed versions immediately. The vulnerabilities were published on 2026-09-17 and 2026-08-24, respectively.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-24
CVE-2026-77635 published
CVE-2026-77635 disclosed, affecting CakePHP versions prior to 5.1.10, 5.2.15, and 5.3.7.
Sploitus
2026-09-17
CVE-2026-79752 published
CVE-2026-79752 disclosed, affecting CakePHP versions prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Sploitus
2026-09-19
Patches released for vulnerabilities
CakePHP released updates to fix the critical SQL injection vulnerabilities, urging users to upgrade immediately.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-77635 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed