CVE-2026-41478 Details
Description
Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a SQL injection vulnerability in Saltcorn’s mobile-sync routes allows any authenticated low-privilege user with read access to at least one table to inject arbitrary SQL through sync parameters. This can lead to full database exfiltration, including admin password hashes and configuration secrets, and may also enable database modification or destruction depending on the backend. This vulnerability is fixed in 1.4.6, 1.5.6, and 1.6.0-beta.5.
A SQL injection vulnerability has been identified in Saltcorn versions prior to 1.4.6, 1.5.6, and 1.6.0-beta.5. This vulnerability exists in the mobile-sync routes, specifically `POST /sync/load_changes` and `POST /sync/deletes`. It allows authenticated low-privilege users with read access to at least one table to inject arbitrary SQL through sync parameters. The exploitation of this vulnerability could lead to full database exfiltration, including admin password hashes and configuration secrets, and may also allow for database modification or destruction, depending on the backend.
Users can upgrade to Saltcorn versions 1.4.6, 1.5.6, or 1.6.0-beta.5 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/saltcorn/saltcorn/security/advisories/GHSA-jp74-mfrx-3qvh | CISA-ADP | Vendor Advisory |
| https://github.com/saltcorn/saltcorn/security/advisories/GHSA-jp74-mfrx-3qvh | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| saltcorn saltcorn | < 1.4.6 >= 1.5.0, < 1.5.6 1.6.0 alpha0 1.6.0 alpha1 1.6.0 alpha10 1.6.0 alpha11 1.6.0 alpha12 1.6.0 alpha13 1.6.0 alpha14 1.6.0 alpha15 1.6.0 alpha16 1.6.0 alpha17 1.6.0 alpha2 1.6.0 alpha3 1.6.0 alpha4 1.6.0 alpha5 1.6.0 alpha6 1.6.0 alpha7 1.6.0 alpha8 1.6.0 alpha9 1.6.0 beta1 1.6.0 beta2 1.6.0 beta3 1.6.0 beta4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |