CVE-2026-72599
Last modified
CVE-2026-72599 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause.
Description
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| e107 | e107 | <= 2.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-72599?
How severe is CVE-2026-72599?
How do I fix CVE-2026-72599?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-72593A missing authentication vulnerability in dulldusk/phpfm thr…9.8
- CVE-2026-72594A stored cross-site scripting (XSS) vulnerability in lobehub…7.6
- CVE-2026-72595A broken access control vulnerability in BadChoice Handesk a…8.1
- CVE-2026-72596A broken access control vulnerability in Ghost Foundation Gh…8.1
- CVE-2026-72597A server-side request forgery vulnerability in Friendica thr…6.5
- CVE-2026-72598A server-side request forgery vulnerability in Apioo Fusio 8…6.5
- CVE-2026-7260Circular symbolic links in phar archives could lead to unbou…5.5
- CVE-2026-72600A broken access control vulnerability in Idurar IDURAR ERP C…7.5
- CVE-2026-72601A broken access control vulnerability in CSZ CMS 1.3.2 allow…7.5
- CVE-2026-72602A path traversal vulnerability in AsyncFuncAI deepwiki-open …7.5
- CVE-2026-72603An OS command injection vulnerability in wg-easy 15.3.0 allo…9.9
- CVE-2026-72604A path traversal vulnerability in Intelliants Subrion CMS th…6.5
Are you affected by CVE-2026-72599?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
