


Perceptive Security
SOC/SIEM Consultancy

An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an aut…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 09:01:28
Source:
nvd.nist.gov
Web Technologies, Database & Storage
An SQL injection vulnerability has been discovered in Mautic's API contact filtering mechanism. The vulnerability stems from insufficient recursive sanitization of nested query parameters, allowing authenticated API users to bypass input filtering. Attackers can exploit this flaw to inject arbitrary SQL commands into the database. This represents a significant security risk as it could lead to unauthorized data access, modification, or deletion. The vulnerability affects Mautic's API functionality specifically related to contact filtering operations.
Technical details
Mitigation steps:
Affected products:
Mautic
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4776
https://github.com/mautic/mautic/security/advisories/GHSA-fcmw-wx57-9p75
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
