CVE-2026-67917: SQL Injection
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The azuracast:restore command executes the db.sql file extracted from a backup archive without any content validation or sanitization. This allows a remote attacker to escalate privileges
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
zuraCastto a version that resolves this vulnerability.Fixed in 0.23.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67917?
CVE-2026-67917 has a risk score of 55, indicating a moderate severity level.
How do I fix CVE-2026-67917?
To fix CVE-2026-67917, upgrade zuraCast to a version newer than 0.23.7 that addresses the SQL injection vulnerability.
What type of vulnerability is CVE-2026-67917?
CVE-2026-67917 is a SQL injection vulnerability affecting zuraCast's backup restore functionality.
Can CVE-2026-67917 be exploited remotely?
Yes, CVE-2026-67917 can be exploited remotely by an attacker to escalate privileges.
What functionality is affected by CVE-2026-67917?
CVE-2026-67917 affects the backup restore functionality in zuraCast, specifically the execution of the db.sql file.