SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-54646

An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database…

EXPLOITHIGH 7.2EPSS 1.45%

Does this matter?

A public exploit is published in Exploit-DB and the impact is high, while EPSS rates exploitation at 1.4%. Anyone can run this; patch or mitigate before the next change window and check exposed instances for signs of use.

Description

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.45% probability · 72th percentile
Public exploits
1 in Exploit-DB · first 31 August 2026
CISA KEV
Not listed
Weakness
CWE-89
Source
security-advisories@github.com
EPSS trend
0%3%5%19 September 2026: 1.45%19 September 202619 September 2026

EPSS 1.4% since 19 September 2026; no change recorded yet. Points are recorded when the score first appears and whenever it moves by a percentage point or more.

Public exploits (1)

Entries in Exploit-DB that cite this CVE. Links go to the Exploit-DB page and to the file in the public repository; nothing is hosted here. A verified tick means the Exploit-DB team confirmed the exploit works against the stated version.

EDB-IDTitleTypePublishedVerified
EDB-52663source ↗CubeCart 6.7.4 - SQLmultiple · Mikail KOCADAĞwebapps31 August 2026no

Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.