cvedb.io
CVE-2026-41478
CRITICAL · CVSS 9.9
EPSS exploitation probability: 0%
Published 2026-04-24T21:16:19.353 · Last modified 2026-06-17T10:46:46.407

Summary

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depending on the backend. This vulnerability is fixed in 1.4.6, 1.5.6, and 1.6.0-beta.5.

Affected products

saltcorn — saltcorn

Does this affect you?

Add your gear to cvedb and we'll alert you only when saltcorn ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.