
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3105 is a SQL injection vulnerability in Mautic's Contact Activity API endpoint, where the sort direction parameter was not validated against an allowlist, allowing authenticated users to inject arbitrary SQL commands. It affects Mautic versions 2.10.0 through 4.4.18, 5.0.0 through 5.2.9, 6.0.0 through 6.0.7, and 7.0.0. The vulnerability was disclosed on February 24, 2026, with patches released the same day. The CNA (Mautic) assigned a CVSS v3.1 score of 7.6 (High), while NVD assessed it at 8.8 (High) (GitHub Advisory).
The root cause is improper neutralization of special elements in an SQL command (CWE-89), specifically in the query construction logic for the Contact Activity timeline API. The sort direction parameter — which should only accept values like ASC or DESC — was passed directly into the SQL query without being validated against a strict allowlist, enabling SQL injection via crafted API requests. Exploitation requires only low-level authenticated access (valid credentials) and no user interaction, making it accessible to any authenticated Mautic user. The vulnerability was reported by researcher q1uf3ng and remediated by developers patrykgruszka and escopecz (GitHub Advisory).
Successful exploitation allows authenticated attackers to execute arbitrary SQL commands against the underlying database, potentially resulting in unauthorized access to sensitive marketing data (contacts, campaigns, email lists), modification or deletion of database records, and disruption of service availability. The NVD assessment rates confidentiality, integrity, and availability impacts all as High, reflecting the potential for full database compromise. Given Mautic's role as a marketing automation platform, exposed data may include personally identifiable information (PII) of contacts, which carries significant regulatory and reputational risk (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.03%, indicating a low current probability of exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the low attack complexity and requirement for only low-privilege credentials make it relatively straightforward to exploit once an attacker has valid Mautic credentials.
ASC or DESC with a crafted SQL expression such as ASC,(SELECT SLEEP(5))-- for time-based blind injection or ASC UNION SELECT ... for data extraction).ASC or DESC); unexpected outbound database connections from the Mautic server.SELECT, UNION, SLEEP, --, ') in sort-related query parameters; database error messages logged in Mautic application logs related to malformed SQL queries.Mautic has released patched versions addressing this vulnerability: 4.4.19 (for versions 2.10.0–4.4.18), 5.2.10 (for versions 5.0.0–5.2.9), 6.0.8 (for versions 6.0.0–6.0.7), and 7.0.1 (for version 7.0.0). No workarounds are available; upgrading is the only remediation. Organizations should update at their earliest convenience after taking a backup. Additionally, restricting API access to only users with necessary permissions and monitoring API logs for suspicious sort parameter values are recommended as defense-in-depth measures (GitHub Advisory, Mautic 5.2.10 Release, Mautic 6.0.8 Release, Mautic 7.0.1 Release).
The vulnerability received coverage on social media platforms including Mastodon and Bluesky shortly after disclosure, with security community accounts sharing the advisory. A technical workshop post on dev.to discussed defending APIs against ORDER BY SQL injection in the context of this CVE. The ENISA European Vulnerability Database (EUVD) catalogued the vulnerability as EUVD-2026-8548. No major vendor statements beyond the Mautic security advisory itself have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."