Junglewise Threat Intelligence

CVE-2026-38739: eZ Systems eZ Publish Legacy SQL injection in dfscleanup

CVE-2026-38739 · Severity: high · CVSS 7.1 · Published 2026-05-29

Vendors: Packagist.

Executive brief

eZ Publish Legacy, an older content management system, contains a security flaw in its database cleanup script. An attacker with local access to the server could exploit this to steal sensitive information, such as user credentials, from the database. Because this software is no longer supported, no official fix will be released.

Technical details

A union-based SQL injection vulnerability exists in eZ Publish Legacy within the dfscleanup.php script and the _getFileList function of the eZDFSFileHandlerMySQLiBackend class. The root cause is improper neutralization of special elements used in SQL commands (CWE-89). An attacker with local shell access and sufficient privileges to execute the cleanup script can manipulate database queries to extract sensitive data. This affects version 2019.03 and potentially other legacy branches. No patches are available as the product has reached end-of-life.

Affected products

  • ezsystems ezpublish-legacy 2019.03

Timeline

  • 2026-05-29: advisory: GitHub Advisory GHSA-xg9x-h37w-h3r3 published

References