CVE-2026-3105: SQL Injection in Contact Activity API Sorting
Summary This advisory addresses a SQL Injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API.
Mitigation
Please update to 5.2.10, 6.0.8, 7.0.1 or later.
Workarounds
None.
References
If there are any questions or comments about this advisory:
Email Mautic at security@mautic.org
Other sources
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities. A vulnerability exists in the query construction for the Contact Activity timeline where the parameter responsible for determining the sort direction was not strictly validated against an allowlist, potentially allowing authenticated users to inject arbitrary SQL commands via the API.
MitigationPlease update to 4.4.19, 5.2.10, 6.0.8, 7.0.1 or later.
WorkaroundsNone.
ReferencesIf you have any questions or comments about this advisory:
Email us at security@mautic.org
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3105?
CVE-2026-3105 has a medium severity rating due to its potential for SQL injection attacks in specific API endpoints.
How do I fix CVE-2026-3105?
To fix CVE-2026-3105, update Mautic to a version later than 4.4.19, 5.2.10, 6.0.8, or 7.0.1.
What kind of vulnerability is CVE-2026-3105?
CVE-2026-3105 is a SQL injection vulnerability affecting the Contact Activity API endpoint in Mautic.
Which versions of Mautic are affected by CVE-2026-3105?
Affected versions include Mautic versions up to but not including 4.4.19, 5.2.10, 6.0.8, and 7.0.1.
What can attackers achieve using CVE-2026-3105?
Attackers can exploit CVE-2026-3105 to manipulate SQL queries, potentially leading to unauthorized access to contact activities.