Skip to content
SQL Injection Vulnerability in Drogon Framework Exposes Databases

SQL Injection Vulnerability in Drogon Framework Exposes Databases

First seen 21 Sep 2026, 11:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 13:53 UTC
  • CVE-2026-94143 affects Drogon framework versions up to 1.9.13.
  • The vulnerability allows SQL injection via unvalidated sort parameters.
  • No authentication is required for exploitation, increasing risk for public APIs.

A critical SQL injection vulnerability (CVE-2026-94143) has been identified in the Drogon framework, affecting versions up to 1.9.13. The flaw exists in the Mapper::orderBy function, allowing remote attackers to exploit unvalidated sort query parameters to execute arbitrary SQL commands. This vulnerability is particularly dangerous as it can be exploited without authentication, making internet-facing applications highly susceptible. The vendor was contacted prior to disclosure but did not respond. While the exploit is now public, there is currently no evidence of active exploitation. Successful attacks could lead to unauthorized database access, data theft, and potential service disruption. Developers using the affected ORM component are urged to implement immediate mitigations and review their configurations. No fixes have been released as of now.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
CVE-2026-94143 published
A SQL injection vulnerability in the Drogon framework was disclosed, affecting versions up to 1.9.13.
Redpacketsecurity
2026-09-21
Vendor contacted but unresponsive
The vendor was notified of the vulnerability prior to public disclosure but did not respond.
Redpacketsecurity
2026-09-21
Public exploit available
The SQL injection exploit has been made public, raising concerns for affected applications.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track Ubuntu and CVE-2026-94143 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed