CVE-2026-4776

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.
Configurations

No configuration.

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección SQL existe en el mecanismo de filtrado de contactos de la API de Mautic. Debido a la insuficiente sanitización recursiva de los parámetros de consulta anidados, un usuario de API autenticado puede eludir el filtrado de entrada e inyectar comandos SQL arbitrarios.

29 May 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 08:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-4776

Mitre link : CVE-2026-4776

CVE.ORG link : CVE-2026-4776


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')