SQL Injection Vulnerability in syslog-ng Products by Syslog-ng
CVE-2026-39879

7.1HIGH

Key Information:

Vendor

Syslog-ng

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-39879?

The syslog-ng application is susceptible to SQL injection caused by a missing sanitization call in the afsql_dd_run_query function. This vulnerability can be exploited by attackers to execute arbitrary SQL commands on the database, leading to unauthorized access to sensitive data. Importantly, this flaw occurs only if the SQL driver is manually configured and is not part of the default configuration. Users are urged to upgrade to syslog-ng version 4.12 or higher, syslog-ng Premium Edition 8.2 or higher, or syslog-ng Store Box 7.8 or higher to mitigate the risk.

Affected Version(s)

syslog-ng < 4.12

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.