AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-72599

CRITICAL · CVSS 9.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL commands through the news item page ID parameter, which is improperly concatenated into a SQL WHERE clause. This critical flaw enables attackers to read, modify, or delete all database contents, including sensitive administrator credentials. Organizations using this version of e107 should prioritize immediate remediation to mitigate the risk of unauthorized access and data compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72599
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%

Original NVD Description

An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.