SQL Injection Vulnerability in CakePHP Framework Affecting PostgreSQL Driver
CVE-2026-77635

9.2CRITICAL

Key Information:

Vendor

CakePHP

Vendor
CVE Published:
24 August 2026

What is CVE-2026-77635?

The CakePHP Framework has a vulnerability when using the PostgreSQL Driver's FunctionsBuilder::jsonValue() method with user-controlled data in the jsonPath parameter. This vulnerability allows attackers to perform SQL injection attacks, which may lead to unauthorized data access or manipulation. Users are advised to upgrade to the patched versions: 5.1.10, 5.2.15, or 5.3.7 to mitigate these risks effectively.

Affected Version(s)

cakephp >= 5.1.0, < 5.1.10 < 5.1.0, 5.1.10

cakephp >= 5.2.0, < 5.2.15 < 5.2.0, 5.2.15

cakephp >= 5.3.0, < 5.3.7 < 5.3.0, 5.3.7

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.