Description
Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.
Published: 2026-09-30
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection leading to database corruption
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a caller to supply a crafted source database name to the sqlcipher_export convenience function. The function temporarily clears defensive restrictions while performing dynamic schema manipulation, and a flaw in handling the source name permits execution of arbitrary SQL statements that would normally be blocked. This can lead to modifications of the sqlite_schema table and cause database corruption. The weakness is tracked as CWE-89, reflecting unsanitized SQL input.

Affected Systems

Zetetic SQLCipher versions prior to 4.15.0 are affected. The issue concerns the sqlcipher_export function available in these releases and applies to any database instance accessed by users of those versions.

Risk and Exploitability

Based on the description, it is inferred that the attacker would need local or application-level access to supply a crafted source database name to sqlcipher_export. The CVSS score of 2.1 indicates low overall severity, and no EPSS information is available, so the statistical exploitation likelihood is unknown. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation would corrupt the database and could result in data loss, but the impact is limited to the database instance being operated on.

Generated by OpenCVE AI on September 30, 2026 at 07:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SQLCipher 4.15.0 or later, which implements proper validation of the source database name in sqlcipher_export.
  • Modify application code to perform strict validation or sanitization of the source database name before invoking the sqlcipher_export function, ensuring it contains only legitimate database identifiers.
  • Restrict the use of the sqlcipher_export function to trusted processes or users, for example by limiting the function's exposure or implementing role-based access controls.

Generated by OpenCVE AI on September 30, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in SQLCipher Export Function

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description Zetetic SQLCipher before 4.15.0 allows SQL injection. The sqlcipher_export convenience function can be used to copy the contents of one attached database into another. It is most often used to convert between plaintext and encrypted databases. It needs to do dynamic schema manipulation, and thus the function temporarily clears defensive restrictions during operation. A vulnerability in the handling of the source database name parameter made it possible for a caller to supply a crafted source name, which could execute statements that defensive mode would otherwise block. This could allow direct modifications to the sqlite_schema table and database corruption. SQLCipher 4.15.0 now strictly validates the source database name and prevents the bypass.
First Time appeared Zetetic
Zetetic sqlcipher
Weaknesses CWE-89
CPEs cpe:2.3:a:zetetic:sqlcipher:*:*:*:*:*:*:*:*
Vendors & Products Zetetic
Zetetic sqlcipher
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L'}


Subscriptions

Zetetic Sqlcipher
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T00:19:30.222Z

Reserved: 2026-06-08T01:02:33.711Z

Link: CVE-2026-51936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T01:16:37.520

Modified: 2026-09-30T01:16:37.520

Link: CVE-2026-51936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')