CVE-2026-26794: SQL Injection
Published Mar 12, 2026
·Updated
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the addgroup() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request.
Affected Software
3 affected components
gl-inet GL-AR300M16
All of the following
gl-inet Ar300m16 Firmware=4.3.11
gl-inet AR300M16
Event History
Mar 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26794?
CVE-2026-26794 has been classified with a high severity due to its SQL injection capabilities.
2
How do I fix CVE-2026-26794?
To fix CVE-2026-26794, update the firmware of GL-iNet GL-AR300M16 to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2026-26794?
CVE-2026-26794 affects GL-iNet GL-AR300M16 with firmware version 4.3.11.
4
Can CVE-2026-26794 be exploited remotely?
Yes, CVE-2026-26794 can be exploited remotely via a crafted HTTP request.
5
What types of exploits are possible with CVE-2026-26794?
Exploiting CVE-2026-26794 allows attackers to execute arbitrary SQL database operations.