CVE-2026-4317
published 2026-03-31CVE-2026-4317: SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to…
PriorityP261critical9.3CVSS 4.0
AVNACLATNPRLUINVCHVIHVALSCNSINSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.34%
26.3th percentile
SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value of the 'timezone' request parameter by including malicious characters and SQL payload. The application would interpolate these values directly into the SQL query without first performing proper filtering or sanitization (e.g., using functions such as 'prisma.rawQuery', 'prisma.$queryRawUnsafe' or raw queries with 'ClickHouse'). The successful explotation of this vulnerability could allow an authenticated attacker to compromiso the data of the database and execute dangerous functions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| umami_software_application | umami_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Umami Software application 3.0.2 Request Parameter prisma.rawQuery/prisma.queryRawUnsafe sql injection
vuldb·2026-05-20·CVSS 9.3
CVE-2026-4317 [CRITICAL] Umami Software application 3.0.2 Request Parameter prisma.rawQuery/prisma.queryRawUnsafe sql injection
A vulnerability has been found in Umami Software application 3.0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Request Parameter Handler. This manipulation of the argument prisma.rawQuery/prisma.queryRawUnsafe causes sql injection.
This vulnerability appears as CVE-2026-4317. The attack may be initiated remotely. There is no available exploit.
GHSA
GHSA-r66v-9cpq-347q: SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated att
ghsa_unreviewed·2026-03-31
CVE-2026-4317 [CRITICAL] CWE-89 GHSA-r66v-9cpq-347q: SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated att
SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value of the 'timezone' request parameter by including malicious characters and SQL payload. The application would interpolate these values directly into the SQL query without first performing proper filtering or sanitization (e.g., using functions such as 'prisma.rawQuery', 'prisma.$queryRawUnsafe' or raw queries with 'ClickHouse'). The successful explotation of this vulnerability could allow an authenticated attacker to compromiso the data of the database and execute dangerous functions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-03-31
Published