CVE-2026-39358: CubeCart: Time-based Blind SQL Injection
CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sortactivity, sortadmin, and sortcustomer) of the Products and Logs endpoints in CubeCart v6.x. This allows an attacker to execute arbitrary SQL commands, compromising the confidentiality and integrity of the database. This vulnerability is fixed in 6.6.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39358?
CVE-2026-39358 is considered a high-severity vulnerability due to its potential for time-based blind SQL injection exploits.
How do I fix CVE-2026-39358?
To mitigate CVE-2026-39358, upgrade CubeCart to version 6.6.0 or later where the vulnerability is resolved.
What components of CubeCart are affected by CVE-2026-39358?
CVE-2026-39358 affects the sorting parameters in the Products and Logs endpoints of CubeCart prior to version 6.6.0.
Can CVE-2026-39358 be exploited without authentication?
No, CVE-2026-39358 requires authentication to exploit due to the nature of the vulnerable endpoints.
What are the potential impacts of exploiting CVE-2026-39358?
Exploiting CVE-2026-39358 could lead to unauthorized access to the database, allowing attackers to retrieve sensitive data.