Total Database Collapse: Inside the ElectricSQL CVSS 10.0 SQL Injection
ID: 0ccb5c35-a50d-5ec8-85d4-67f8454edef4
STIX ID: report--0ccb5c35-a50d-5ec8-85d4-67f8454edef4
Feed Name: securityonline.info
ElectricSQL disclosed a critical SQL injection vulnerability (CVE-2026-40906, CVSS 10.0) in the ElectricSQL/v1/shape API order_by parameter that permits authenticated users to inject malicious SQL, extract data via error messages, execute arbitrary write/delete statements using dblink_exec, create superuser roles, and cause DoS via pg_sleep; the flaw can break tenant isolation in multi-tenant databases. ElectricSQL fixed the issue in version 1.5.0 by replacing a permissive wildcard with a deny-by-default allowlist and adding an AST rebuild to ensure only normalized SQL reaches the database, and reports no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
