PT-2026-93845 · Mikroorm · Mikroorm

CVE-2026-84993

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MikroORM versions prior to 6.6.16 MikroORM versions prior to 7.1.7
Description The shared SQL layer validates the field key of an orderBy clause but fails to validate its direction value before the AbstractSqlPlatform.getOrderByExpression() function concatenates it into an ORDER BY clause. This allows applications that bind attacker-controlled request data to the direction in em.find(), em.findOne(), em.findAndCount(), QueryBuilder.orderBy(), or QueryBuilderHelper.getQueryOrderFromObject() to permit a raw SQL fragment. This can lead to blind or boolean extraction of data accessible to the database account. This issue affects SQLite, PostgreSQL, MySQL, MariaDB, MSSQL, libSQL, and Oracle drivers.
Recommendations Update to version 6.6.16. Update to version 7.1.7.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84993
GHSA-7J79-7Q93-6V69

Affected Products

Mikroorm