SQL Injection Vulnerability in syslog-ng Products by Syslog-ng
CVE-2026-39879
7.1HIGH
What is CVE-2026-39879?
The syslog-ng application is susceptible to SQL injection caused by a missing sanitization call in the afsql_dd_run_query function. This vulnerability can be exploited by attackers to execute arbitrary SQL commands on the database, leading to unauthorized access to sensitive data. Importantly, this flaw occurs only if the SQL driver is manually configured and is not part of the default configuration. Users are urged to upgrade to syslog-ng version 4.12 or higher, syslog-ng Premium Edition 8.2 or higher, or syslog-ng Store Box 7.8 or higher to mitigate the risk.
Affected Version(s)
syslog-ng < 4.12
