HarborGuard / CVE
Back to search
HIGHCVE-2026-42031Published Modified CNA GitHub_M

CVE-2026-42031: CKAN: Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5.

Metrics

CVSS v4.0
8.3
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • ckan / ckan
    >= 2.11.0, < 2.11.5 · < 2.10.10
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N