


Perceptive Security
SOC/SIEM Consultancy

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL inject…
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 22:04:46
Source:
nvd.nist.gov
Database & Storage, Web Technologies
Electric, a Postgres sync engine, contains a critical SQL injection vulnerability in the order_by parameter of the /v1/shape API endpoint. The vulnerability affects versions 1.1.12 to before 1.5.0 and allows authenticated users to perform error-based SQL injection attacks. Attackers can read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. The vulnerability has been fixed in version 1.5.0.
Technical details
Mitigation steps:
Affected products:
Electric
ElectricSQL
PostgreSQL
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-40906
https://github.com/electric-sql/electric/pull/4081
https://github.com/electric-sql/electric/security/advisories/GHSA-h5rg-pxx7-r2hj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
