CVE-2026-54646
An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database…
Does this matter?
A public exploit is published in Exploit-DB and the impact is high, while EPSS rates exploitation at 1.4%. Anyone can run this; patch or mitigate before the next change window and check exposed instances for signs of use.
Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.45% probability · 72th percentile
- Public exploits
- 1 in Exploit-DB · first 31 August 2026
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Source
- security-advisories@github.com
EPSS 1.4% since 19 September 2026; no change recorded yet. Points are recorded when the score first appears and whenever it moves by a percentage point or more.
Public exploits (1)
Entries in Exploit-DB that cite this CVE. Links go to the Exploit-DB page and to the file in the public repository; nothing is hosted here. A verified tick means the Exploit-DB team confirmed the exploit works against the stated version.
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA, exploits from Exploit-DB. Refreshed daily. Download this record as JSON.