CVE-2026-14920: AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter
Published Aug 2, 2026
·Updated
Summary
Affected Software
1 affected component
AcyMailing AcyMailing<10.11.1
Event History
Aug 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-14920?
CVE-2026-14920 has a risk score of 76, indicating it is considered a high severity vulnerability.
2
What type of vulnerability is CVE-2026-14920?
CVE-2026-14920 is classified as an Unauthenticated SQL Injection vulnerability.
3
How do I fix CVE-2026-14920?
To fix CVE-2026-14920, upgrade AcyMailing to version 10.11.1 or later.
4
What software is affected by CVE-2026-14920?
CVE-2026-14920 affects AcyMailing versions prior to 10.11.1.
5
Is CVE-2026-14920 exploitable remotely?
Yes, CVE-2026-14920 is exploitable remotely without authentication.