An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

There are no official workarounds. To mitigate this issue without upgrading, you may temporarily disable API access or restrict API permissions to highly trusted accounts.

History

Fri, 29 May 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 09:15:00 +0000

Type Values Removed Values Added
Title SQL Injection via API Contact Filtering in Mautic

Fri, 29 May 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Mautic
Mautic mautic
Vendors & Products Mautic
Mautic mautic

Fri, 29 May 2026 07:45:00 +0000

Type Values Removed Values Added
Description An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mautic

Published:

Updated: 2026-05-29T11:41:44.104Z

Reserved: 2026-03-24T15:00:12.560Z

Link: CVE-2026-4776

cve-icon Vulnrichment

Updated: 2026-05-29T11:41:38.393Z

cve-icon NVD

Status : Deferred

Published: 2026-05-29T08:16:19.260

Modified: 2026-05-29T15:39:34.620

Link: CVE-2026-4776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T09:00:13Z

Weaknesses