CVE-2026-71245: Mautic - SQL Injection via field Parameter in Lead-by-Field-Value AJAX Endpoint
Published Aug 5, 2026
·Updated
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
Affected Software
1 affected component
Mautic Mautic
Event History
Aug 5, 2026
CVE Published
via MITRE·10:56 AM
Rejected
via MITRE·10:56 AM
Data Sourced
via NVD·11:16 AM
Description
Aug 17, 2026
Rejected
via MITRE·01:59 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-71245?
CVE-2026-71245 has a high severity rating of 7.1.
2
What type of vulnerability is CVE-2026-71245?
CVE-2026-71245 is a SQL Injection vulnerability affecting Mautic.
3
How does CVE-2026-71245 affect Mautic?
This vulnerability allows attackers to exploit the field parameter in the Lead-by-Field-Value AJAX endpoint to execute arbitrary SQL queries.
4
How do I fix CVE-2026-71245?
To mitigate CVE-2026-71245, sanitize inputs thoroughly and apply security patches from the Mautic repository.
5
What is the potential impact of CVE-2026-71245?
CVE-2026-71245 can lead to unauthorized access to sensitive data through SQL Injection.