CVE-2026-3105: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-3105 is a SQL injection vulnerability in Mautic's Contact Activity API endpoint, where the sort direction parameter was not validated against an allowlist, allowing authenticated users to inject arbitrary SQL commands. It affects Mautic versions 2.10.0 through 4.4.18, 5.0.0 through 5.2.9, 6.0.0 through 6.0.7, and 7.0.0. The vulnerability was disclosed on February 24, 2026, with patches released the same day. The CNA (Mautic) assigned a CVSS v3.1 score of 7.6 (High), while NVD assessed it at 8.8 (High) (GitHub Advisory).

Technical details

The root cause is improper neutralization of special elements in an SQL command (CWE-89), specifically in the query construction logic for the Contact Activity timeline API. The sort direction parameter — which should only accept values like ASC or DESC — was passed directly into the SQL query without being validated against a strict allowlist, enabling SQL injection via crafted API requests. Exploitation requires only low-level authenticated access (valid credentials) and no user interaction, making it accessible to any authenticated Mautic user. The vulnerability was reported by researcher q1uf3ng and remediated by developers patrykgruszka and escopecz (GitHub Advisory).

Impact

Successful exploitation allows authenticated attackers to execute arbitrary SQL commands against the underlying database, potentially resulting in unauthorized access to sensitive marketing data (contacts, campaigns, email lists), modification or deletion of database records, and disruption of service availability. The NVD assessment rates confidentiality, integrity, and availability impacts all as High, reflecting the potential for full database compromise. Given Mautic's role as a marketing automation platform, exposed data may include personally identifiable information (PII) of contacts, which carries significant regulatory and reputational risk (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.03%, indicating a low current probability of exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the low attack complexity and requirement for only low-privilege credentials make it relatively straightforward to exploit once an attacker has valid Mautic credentials.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Mautic instances running versions 2.10.0–4.4.18, 5.0.0–5.2.9, 6.0.0–6.0.7, or 7.0.0 using tools like Shodan or Censys, searching for Mautic login pages or API endpoints.
  2. Obtain credentials: Acquire valid Mautic user credentials through phishing, credential stuffing, or use of a low-privilege account (any authenticated user is sufficient).
  3. Authenticate to the API: Use the Mautic REST API to authenticate and obtain a valid session token or OAuth credentials.
  4. Craft malicious request: Send an API request to the Contact Activity timeline endpoint, injecting SQL payload into the sort direction parameter (e.g., replacing ASC or DESC with a crafted SQL expression such as ASC,(SELECT SLEEP(5))-- for time-based blind injection or ASC UNION SELECT ... for data extraction).
  5. Extract or manipulate data: Use standard SQL injection techniques (UNION-based, error-based, or blind/time-based) to enumerate database tables, extract sensitive contact data, modify records, or escalate privileges within the database (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated API requests to the Mautic Contact Activity endpoint with non-standard sort direction parameter values (anything other than ASC or DESC); unexpected outbound database connections from the Mautic server.
  • Logs: Mautic API access logs showing requests with SQL keywords (SELECT, UNION, SLEEP, --, ') in sort-related query parameters; database error messages logged in Mautic application logs related to malformed SQL queries.
  • Application Behavior: Unexplained delays in API responses (indicative of time-based blind SQL injection); unexpected changes to contact records or database content; anomalous query patterns in database slow query logs.

Mitigation and workarounds

Mautic has released patched versions addressing this vulnerability: 4.4.19 (for versions 2.10.0–4.4.18), 5.2.10 (for versions 5.0.0–5.2.9), 6.0.8 (for versions 6.0.0–6.0.7), and 7.0.1 (for version 7.0.0). No workarounds are available; upgrading is the only remediation. Organizations should update at their earliest convenience after taking a backup. Additionally, restricting API access to only users with necessary permissions and monitoring API logs for suspicious sort parameter values are recommended as defense-in-depth measures (GitHub Advisory, Mautic 5.2.10 Release, Mautic 6.0.8 Release, Mautic 7.0.1 Release).

Community reactions

The vulnerability received coverage on social media platforms including Mastodon and Bluesky shortly after disclosure, with security community accounts sharing the advisory. A technical workshop post on dev.to discussed defending APIs against ORDER BY SQL injection in the context of this CVE. The ENISA European Vulnerability Database (EUVD) catalogued the vulnerability as EUVD-2026-8548. No major vendor statements beyond the Mautic security advisory itself have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management