Mautic SQL Injection Vulnerability in API Contact Filtering

Vulnerability

A SQL injection vulnerability has been identified in Mautic's API contact filtering system, affecting versions 2.6.0 and later. This vulnerability arises from inadequate recursive sanitization of nested query parameters, allowing authenticated API users to bypass input filters and inject arbitrary SQL commands. Exploitation of this vulnerability could enable unauthorized access to sensitive database information, including user credentials, system configurations, and personal identifiable information (PII) of contacts.

Impact

Exploitation of this vulnerability allows authenticated users with API access to execute arbitrary SQL queries on the database. This could lead to unauthorized access to sensitive data, such as user credentials and personal information of contacts, bypassing normal data access permissions.

Remediation

Users are advised to upgrade to Mautic versions 7.1.2, 6.0.9, 5.2.11, or 4.4.20. If an immediate upgrade is not possible, API access can be temporarily disabled or restricted to trusted accounts.

Added: May 29, 2026, 8:19 AM
Updated: May 29, 2026, 8:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
5.4
remediation
7.9
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.