{"id":"CVE-2026-54646","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-54646","generatedAt":"2026-09-20T15:03:29.088Z","title":"An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database…","description":"CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5.","published":"2026-09-17T22:17:03.000Z","lastModified":"2026-09-18T19:16:44.000Z","status":"Received","sourceIdentifier":"security-advisories@github.com","cvss":{"version":"3.1","score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"cwe":["CWE-89"],"affected":[],"epss":{"score":0.01447,"percentile":0.72134,"date":"2026-09-19","history":[]},"kev":{"listed":false},"exploits":{"count":1,"verified":false,"firstPublished":"2026-08-31","source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[{"edbId":52663,"kind":"exploit","title":"CubeCart 6.7.4 - SQL","url":"https://www.exploit-db.com/exploits/52663","sourceUrl":"https://gitlab.com/exploit-database/exploitdb/-/blob/main/exploits/multiple/webapps/52663.txt","file":"exploits/multiple/webapps/52663.txt","published":"2026-08-31","added":"2026-08-31","updated":"2026-08-31","author":"Mikail KOCADAĞ","type":"webapps","platform":"multiple","port":null,"verified":false,"codes":["CVE-2026-54646"],"tags":null,"aliases":null,"applicationUrl":null,"screenshotUrl":null,"referenceUrl":null}]},"verdict":{"level":"urgent","text":"A public exploit is published in Exploit-DB and the impact is high, while EPSS rates exploitation at 1.4%. Anyone can run this; patch or mitigate before the next change window and check exposed instances for signs of use."},"changes":[{"kind":"exploit","label":"Public exploit","at":"2026-08-31T00:00:00.000Z","detail":{"type":"webapps","edbId":52663,"title":"CubeCart 6.7.4 - SQL","platform":"multiple","verified":false,"publishedAt":"2026-08-31"},"summary":"Public exploit published in Exploit-DB: CubeCart 6.7.4 - SQL (webapps, multiple)."}],"references":[{"url":"https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/commit/fc08d55628191969f2345d06d862df316f7d44d3","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/releases/tag/6.7.5","source":"security-advisories@github.com"},{"url":"https://github.com/cubecart/v6/security/advisories/GHSA-qcx6-cg43-ffmx","source":"security-advisories@github.com"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-54646","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}