gist.github.com SQL Injection Vulnerability in Drogon Framework Exposes Databases
Article Content
- •CVE-2026-94143 affects Drogon framework versions up to 1.9.13.
- •The vulnerability allows SQL injection via unvalidated sort parameters.
- •No authentication is required for exploitation, increasing risk for public APIs.
A critical SQL injection vulnerability (CVE-2026-94143) has been identified in the Drogon framework, affecting versions up to 1.9.13. The flaw exists in the Mapper::orderBy function, allowing remote attackers to exploit unvalidated sort query parameters to execute arbitrary SQL commands. This vulnerability is particularly dangerous as it can be exploited without authentication, making internet-facing applications highly susceptible. The vendor was contacted prior to disclosure but did not respond. While the exploit is now public, there is currently no evidence of active exploitation. Successful attacks could lead to unauthorized database access, data theft, and potential service disruption. Developers using the affected ORM component are urged to implement immediate mitigations and review their configurations. No fixes have been released as of now.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ubuntu and CVE-2026-94143 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…