Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 PHP packages GHSA-vjqc-q4mp-2rvf CVE-2026-79752 PKSA-ny8z-1rqf-8z42 PKSA-vxgj-bmcq-9b6x

CakePHP SQL Injection Vulnerability in FunctionsBuilder (CVE-2026-79752)

CakePHP's FunctionsBuilder class fails to properly escape user-controlled dataType, part, and unit values, allowing SQL injection when applications pass untrusted input to affected query-building methods. Fixed versions are available for all supported release lines.

AI summary

A SQL injection vulnerability has been identified in CakePHP, a widely used PHP development framework. The issue affects specific methods in the framework's query-building component and can allow attackers to manipulate SQL queries if an application passes untrusted data to the affected functions. Fixed versions have been released across all actively maintained CakePHP release lines.

What Happened

A SQL injection vulnerability, tracked as CVE-2026-79752, was identified in CakePHP's FunctionsBuilder class, located in src/Database/FunctionsBuilder.php. The affected methods — cast, extract, datePart, and dateAdd — accept dataType, part, or unit parameters that are incorporated directly into generated SQL as unescaped structural fragments rather than being properly sanitized or parameterized.

Technical Cause

The root cause is improper neutralization of special elements used in SQL commands (CWE-89). The affected FunctionsBuilder methods build SQL fragments using the supplied dataType, part, or unit values without escaping them, treating them as trusted structural SQL syntax rather than data. If an application passes untrusted, user-controlled input into these parameters, an attacker can inject arbitrary SQL into the generated query.

Why It Matters

Successful exploitation can allow an attacker to read, modify, or delete data within the application's database, with impact scoped to the privileges of the underlying database connection. Because the vulnerability affects confidentiality, integrity, and availability, and does not require authentication or user interaction when exploitable input paths exist, it poses a significant risk to applications that expose the affected FunctionsBuilder methods to untrusted input.

Who Is Affected

Applications using the cakephp/database or cakephp/cakephp packages that call FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, or FunctionsBuilder::dateAdd with data that originates from untrusted or user-controlled sources are affected. Applications that do not pass external input to these specific methods are not exposed to this issue.

Affected Versions

For cakephp/database: versions from 3.0.0 up to but not including 4.5.12 are affected, as well as versions 4.6.0 up to but not including 4.6.5, 5.0.0 up to but not including 5.1.9, 5.2.0 up to but not including 5.2.14, and 5.3.0 up to but not including 5.3.7. For cakephp/cakephp: versions prior to 4.5.12 are affected, as well as 4.6.0 up to but not including 4.6.5, 5.0.0 up to but not including 5.1.9, 5.2.0 up to but not including 5.2.14, and 5.3.0 up to but not including 5.3.7.

Fixes and Mitigation

Fixed versions are available for both affected packages: 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7. Applications should upgrade to the appropriate fixed version within their release line.

Recommended Action

Upgrade cakephp/database and/or cakephp/cakephp to the fixed version applicable to your current release line (4.5.12, 4.6.5, 5.1.9, 5.2.14, or 5.3.7). Review any application code that passes dynamic or user-controlled values to FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, or FunctionsBuilder::dateAdd, and ensure such input is validated or restricted to a known-safe set of values as a defense-in-depth measure alongside the framework update.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 9.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This issue carries a CVSS base score of 9.2, reflecting the potential for severe confidentiality, integrity, and availability impact if exploited, since successful SQL injection can grant an attacker broad access to the underlying database. PatchBriefing's computed score of 5.9 reflects that the base CVSS severity is the dominant factor, with additional weight given to the fact that exploitation requires no authentication or user interaction in vulnerable code paths. The score is tempered because there is no evidence of known exploitation in the wild, no public exploit code, and a fix is already available, which lowers urgency relative to actively exploited flaws.

Affected versions

cakephp/database >= 3.0.0, < 4.5.12
vulnerable
cakephp/database >=3.0.0,<4.5.12|>=5.3.0,<5.3.7|>=5.2.0,<5.2.14|>=5.0.0,<5.1.9|>=4.6.0,<4.6.5
vulnerable
≥ 4.6.5
patched
≥ 5.1.9
patched
≥ 5.2.14
patched
≥ 5.3.7
patched
≥ 4.5.12
patched
cakephp/cakephp >= 5.3.0, < 5.3.7
vulnerable
cakephp/cakephp >=5.3.0,<5.3.7|>=5.2.0,<5.2.14|>=5.0.0,<5.1.9|>=4.6.0,<4.6.5|<4.5.12
vulnerable
≥ 4.5.12
patched
≥ 4.6.5
patched
≥ 5.1.9
patched
≥ 5.2.14
patched
≥ 5.3.7
patched

Reported fixes

Fixed versions are available for both affected packages: 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7. Applications should upgrade to the appropriate fixed version within their release line.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
CakePHP SQL Injection Vulnerability in FunctionsBuilder (CVE-2026-79752)
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email