OCTOBER 3, 2026
Live Feed
Back to database
Case File

CVE-2026-71245

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-09-04

CyberRota Analysis

AI-Generated

Mautic's getLeadIdsByFieldValueAction is vulnerable due to insufficient sanitization of user input, allowing an attacker to inject SQL through the field name parameter, which is directly concatenated into a SQL query without proper validation. This vulnerability can lead to unauthorized data access or manipulation, posing a significant risk to the integrity of the database. Organizations using Mautic should prioritize addressing this issue, especially those with authenticated user access, to prevent potential exploitation.

CVE
CVE-2026-71245
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.