← Back to browse · API

CVE-2026-41478

Severity
CRITICAL
CVSS
10.0
EPSS
0.00264
Risk score
40.09
CISA KEV
No
PoC
No
Published
2026-04-24
Modified
2026-04-27
First seen
2026-08-07
Aliases
EUVD-2026-25633
Products
saltcorn:saltcorn 1.5.0-beta.0, < 1.5.6, saltcorn:saltcorn 1.6.0-alpha.0, < 1.6.0-beta.5, saltcorn:saltcorn < 1.4.6
Sources
euvd EUVD-2026-25633

Description

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depending on the backend. This vulnerability is fixed in 1.4.6, 1.5.6, and 1.6.0-beta.5.

References