Critical 9.8 CVSS: Severe SQL Injection Flaw Exposed in Marten .NET Document Store Engine
ID: 55e41f62-4491-5afe-a91a-7ba24c0996fa
STIX ID: report--55e41f62-4491-5afe-a91a-7ba24c0996fa
Feed Name: securityonline.info
Threat Score
A critical SQL injection vulnerability (CVE-2026-45288, CVSS 9.8) in Marten’s full-text search API allows untrusted regConfig input to be interpolated into generated SQL, enabling arbitrary command execution (data exfiltration, DDL modifications, DoS). Marten patched the issue in version 8.36.1 by validating regConfig with a strict regex; recommended mitigations include upgrading, hard-coding regConfig, or validating inputs against an allowlist or the provided regex.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
