CVE-2026-44047: SQL injection in MySQL CNID backend
Published May 21, 2026
·Updated
An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.
Affected Software
1 affected component
Netatalk Netatalk MySQL CNID backend>=3.1.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:33 AM
Data Sourced
via MITRE·07:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44047?
CVE-2026-44047 has a severity score of 8.8, categorized as high.
2
How do I fix CVE-2026-44047?
To fix CVE-2026-44047, update your Netatalk installation to version 4.4.3 or later.
3
What type of vulnerability is CVE-2026-44047?
CVE-2026-44047 is an SQL injection vulnerability.
4
What can an attacker do with CVE-2026-44047?
An attacker can obtain unauthorized access to data, modify data, or cause a denial of service.
5
Which versions of Netatalk are affected by CVE-2026-44047?
Netatalk versions 3.1.0 through 4.4.2 are affected by CVE-2026-44047.