CVE-2026-34018: SQL Injection
Published Apr 17, 2026
·Updated
An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.
Affected Software
2 affected components
Cubecart CubeCart<6.6.0
Cubecart CubeCart<6.6.0
Event History
Apr 17, 2026
CVE Published
via MITRE·04:33 AM
Data Sourced
via MITRE·04:33 AM
DescriptionSeverity
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34018?
CVE-2026-34018 is classified as a high severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2026-34018?
To fix CVE-2026-34018, upgrade CubeCart to version 6.6.0 or later.
3
What types of systems are affected by CVE-2026-34018?
CVE-2026-34018 affects all versions of CubeCart prior to 6.6.0.
4
What are the potential impacts of CVE-2026-34018?
The potential impacts of CVE-2026-34018 include unauthorized access to the database and manipulation of data.
5
Is there a workaround for CVE-2026-34018 before upgrading?
There is no official workaround for CVE-2026-34018, so upgrading is the recommended mitigation.