CVE-2026-4317: SQL inyection in Umami Software application

Published Mar 31, 2026
·
Updated

SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value of the 'timezone' request parameter by including malicious characters and SQL payload. The application would interpolate these values directly into the SQL query without first performing proper filtering or sanitization (e.g., using functions such as 'prisma.rawQuery', 'prisma.$queryRawUnsafe' or raw queries with 'ClickHouse'). The successful explotation of this vulnerability could allow an authenticated attacker to compromiso the data of the database and execute dangerous functions.

Affected Software

1 affected component
Umami Umami

Remediation

Information

The vulnerability has been fixed by Umami Software team in version 3.0.3.

Event History

Mar 31, 2026
CVE Published
via MITRE·09:53 AM
Data Sourced
via MITRE·09:53 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-4317?

The severity of CVE-2026-4317 is considered high due to its potential to allow authenticated attackers to execute arbitrary SQL commands.

2

How do I fix CVE-2026-4317?

To fix CVE-2026-4317, ensure that all user-supplied inputs are properly sanitized and validated before being processed by the SQL database.

3

What are the potential impacts of CVE-2026-4317?

The potential impacts of CVE-2026-4317 include unauthorized access to sensitive database information and the ability to alter or delete database entries.

4

Who is affected by CVE-2026-4317?

CVE-2026-4317 affects users of the Umami Software web application that allow unvalidated inputs in their SQL queries.

5

Is CVE-2026-4317 easy to exploit?

Yes, CVE-2026-4317 can be easily exploited by an authenticated attacker if input sanitization measures are inadequate.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203