PT-2026-94368 · Cakephp · Cakephp

·

CVE-2026-79752

·

Published

2026-09-17

·

Updated

2026-09-19

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CakePHP versions prior to 4.5.12 CakePHP versions prior to 4.6.5 CakePHP versions prior to 5.1.9 CakePHP versions prior to 5.2.14 CakePHP versions prior to 5.3.7
Description Certain methods in src/Database/FunctionsBuilder.php allow user-controlled values to be incorporated into generated SQL as unescaped structural fragments. This can lead to SQL injection, impacting confidentiality, integrity, and availability based on the database connection privileges. The affected functions and their vulnerable parameters are:
  • FunctionsBuilder::cast(): dataType
  • FunctionsBuilder::extract(): part
  • FunctionsBuilder::datePart(): part
  • FunctionsBuilder::dateAdd(): unit
Recommendations Update to version 4.5.12 Update to version 4.6.5 Update to version 5.1.9 Update to version 5.2.14 Update to version 5.3.7 Avoid providing user-controlled data to the dataType, part, and unit parameters of the affected functions.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79752
GHSA-VJQC-Q4MP-2RVF

Affected Products

Cakephp