Junglewise Threat Intelligence

CVE-2026-34099: Guardian language-system SQL injection in job_info.php

CVE-2026-34099 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Executive brief

The Guardian language-system, a tool used for automatic translation and subtitling, contains a critical security flaw. An attacker can use this vulnerability to gain unauthorized access to the underlying database without needing a username or password. This could lead to the theft of sensitive information, including user data, system configurations, and internal records.

Technical details

A SQL injection vulnerability exists in the Guardian language-system due to improper sanitization of the 'id' GET parameter in the job_info.php script. The application passes the user-supplied input directly into a mysqli_query call on line 16. Because no authentication is required to access this endpoint, a remote, unauthenticated attacker can use error-based SQL injection techniques (such as using GTID_SUBSET) to extract sensitive information from the database, including the database version, schema names, and full table contents. The vulnerability is present in versions up to and including the Git commit e42c395.

Affected products

  • Guardian language-system up to and including commit e42c395ec4b03fe62973a669c9209a673838b8a4

Timeline

  • 2026-07-01: disclosed: Initial disclosure by researcher philopentest via VulnCheck and GitHub Gist.
  • 2026-07-01: advisory: NVD and VulnCheck published advisory details.

References