OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-75513

CRITICAL · CVSS 9.1 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Marten versions 7.0.0 to 9.13.0 are vulnerable to SQL injection due to improper handling of attacker-controlled strings in LINQ and tenant-management operations, particularly through dictionary indexer keys and other database interactions. This vulnerability can lead to authorization bypass, blind data exfiltration, and potential data modification if semicolon-batched statements are allowed. Organizations using affected versions should prioritize patching to version 9.13.0 to mitigate these critical risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75513
Severity
CRITICAL
CVSS
9.1
EPSS
0.47%

Original NVD Description

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or parameterization. The primary confirmed vector is a dictionary indexer key used by Where filters in src/Marten/Linq/Members/Dictionaries/DictionaryItemMember.cs. Additional affected sinks include SelectParser.cs, DatabaseScopedTenantPartitions.cs, and DeleteAllForTenant.cs reached through IEventStore.DeleteProjectionProgressAsync, while DictionaryContainsKeyFilter.cs (Newtonsoft serializer only; System.Text.Json is not affected) handles ContainsKey calls. Events/Daemon/Internals/EventLoader.cs contains a related per-tenant partition-pruning literal that the advisory identifies as a defense-in-depth sink. A crafted single quote can escape the generated literal, enabling filter or multi-tenant authorization bypass and blind data exfiltration, and deployments that permit semicolon-batched Npgsql statements may also allow data modification. This issue is fixed in version 9.13.0.