Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5.
Published: 2026-09-17
Score: 7.2 High
EPSS: 1.4% Low
KEV: No
Impact: SQL Identifier Injection leading to arbitrary structural SQL commands
Action: Immediate Patch
AI Analysis

Impact

An authenticated administrator of CubeCart can inject arbitrary structural SQL by terminating a table name with a backtick in maintenance.index.inc.php. The code then treats the injected portion as part of the statement, enabling modifications to database structure or the execution of additional queries. This is a classic SQL identifier injection (CWE-89) that threatens the confidentiality, integrity, and availability of the application’s database.

Affected Systems

CubeCart version 6, all releases before 6.7.5. Those versions embed administrator‑controlled table names into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE commands without validating or escaping backticks, creating an identifiable vulnerability.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate to high severity, while the EPSS of 1% suggests a low overall exploitation probability; the weakness requires authenticated administrator privileges, limiting the attack surface. The vulnerability is not listed in the CISA KEV catalog. The attack vector likely involves an attacker who gains admin credentials or exploits a session hijack to deliver the backtick-bypass payload, which can result in database tampering, data loss, or service interruption.

Generated by OpenCVE AI on September 19, 2026 at 19:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the CubeCart v6.7.5 release or later that removes the backtick injection flaw.
  • Limit access to the administrative interface to trusted IPs or enable multi‑factor authentication for administrators to reduce credential compromise.
  • If an upgrade cannot be performed immediately, configure the database user with the least privileges, removing ALTER TABLE, CHECK TABLE, and ANALYZE permissions to constrain potential damage.

Generated by OpenCVE AI on September 19, 2026 at 19:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart v6
Vendors & Products Cubecart
Cubecart v6
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5.
Title CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:32:29.629Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54646

cve-icon Vulnrichment

Updated: 2026-09-18T17:24:19.198Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:02.570

Modified: 2026-09-23T19:43:31.933

Link: CVE-2026-54646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')