Authenticated SQL Injection in ISPConfig Remote API
CVE-2026-61518
Key Information:
- Vendor
Ispconfig
- Status
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-61518?
The ISPConfig Remote API is susceptible to an authenticated SQL injection vulnerability stemming from improper handling of the primary_id parameter in SQL queries. This flaw allows users with low-privilege permissions to manipulate SQL queries directly, enabling the injection of malicious payloads without using standard protection mechanisms such as parameterized queries or input validation. As a result, attackers can potentially delete or alter records in the control panel database and extract sensitive information, including password hashes and client data, through advanced methods like blind boolean inference.
Affected Version(s)
ispconfig3 3.2.0
ispconfig3 3.2.0
ispconfig3 3.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
