OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-79752

CRITICAL · CVSS 9.2 EPSS 0.62% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The CakePHP framework versions prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7 are vulnerable to SQL injection due to improper handling of user-controlled parameters in the FunctionsBuilder class, which can lead to unauthorized data access and manipulation. This critical vulnerability poses significant risks to applications utilizing affected versions, particularly those with elevated database privileges. Organizations using these versions should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79752
Severity
CRITICAL
CVSS
9.2
EPSS
0.62%

Original NVD Description

CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.