Junglewise Threat Intelligence

CVE-2026-12076: Raytha CMS SQL injection in OData filter parsing

CVE-2026-12076 · Severity: info · CVSS 9.3 · Published 2026-06-30

Executive brief

Raytha CMS, an open-source platform used for building and managing websites, contains a critical security flaw in how it processes database queries. A remote attacker can exploit this vulnerability without needing a username or password to gain full control over the underlying database. This could result in the theft of sensitive customer data, administrative credentials, and a complete compromise of the website's information.

Technical details

A SQL injection vulnerability exists in Raytha CMS within the OData filter parsing pipeline. The flaw allows a remote, unauthenticated attacker to inject arbitrary SQL commands into the underlying PostgreSQL database. This occurs due to improper neutralization of special elements used in SQL commands (CWE-89). Successful exploitation can lead to full database compromise, including the extraction of sensitive credentials. The vulnerability is confirmed in version 1.5.2; however, as vendor contact attempts were unsuccessful, a patch is not currently confirmed and other versions may be affected.

Affected products

  • Raytha Raytha CMS 1.5.2

Timeline

  • 2026-06-30: advisory: Advisory published by CERT.PL and NVD

References