CVE-2026-3105
Last modified
CVE-2026-3105 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 4.4.19, 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API. MitigationPlease update to 4.4.19, 5.2.10, 6.0.8, 7.0.1 or later. WorkaroundsNone. ReferencesIf you have any questions or comments about this advisory: Email us at security@mautic.org
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Acquia | Mautic | >= 2.10.0, < 4.4.19 |
| Acquia | Mautic | >= 5.0.0, < 5.2.10 |
| Acquia | Mautic | >= 6.0.0, < 6.0.8 |
| Acquia | Mautic | >= 7.0.0, < 7.0.1 |
References
- https://github.com/mautic/mautic/security/advisories/GHSA-r5j5-q42h-fc93Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-3105?
How severe is CVE-2026-3105?
How do I fix CVE-2026-3105?
Are you affected by CVE-2026-3105?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
