Description
CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Published: 2026-09-17
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection
Action: Immediate Patch
AI Analysis

Impact

CakePHP’s FunctionsBuilder methods can incorporate user‑controlled dataType, part, or unit values directly into SQL query fragments without escaping. An attacker can thus inject arbitrary SQL statements, resulting in confidentiality loss, data tampering, or denial of service through the privileges of the database connection. The vulnerability is an instance of SQL injection (CWE‑89).

Affected Systems

All CakePHP releases older than 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7 are vulnerable. In particular, the affected functions are FunctionsBuilder::cast, ::extract, ::datePart, and ::dateAdd located in src/Database/FunctionsBuilder.php.

Risk and Exploitability

The CVSS score of 9.2 denotes a critical severity and indicates that exploitation could be highly damaging if the attacker can supply input to the vulnerable methods. Although the EPSS score is not available, the high base score suggests that exploitation scenarios are plausible. The vulnerability is not yet listed in CISA’s KEV catalog, but no public exploits are reported, so the exploitability largely depends on the attacker’s ability to inject data into the application’s query‑building logic.

Generated by OpenCVE AI on September 17, 2026 at 21:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CakePHP to version 4.5.12, 4.6.5, 5.1.9, 5.2.14, or 5.3.7, where the SQL injection flaw is fixed.
  • If an immediate upgrade is infeasible, whitelist acceptable dataType, part, and unit values in the application code to prevent arbitrary SQL fragments from being injected.
  • After mitigation, conduct a security review of all database query construction paths to ensure no other functions accept unchecked user input, focusing on proper input validation and parameterization.

Generated by OpenCVE AI on September 17, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vjqc-q4mp-2rvf CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cakephp
Cakephp cakephp
Vendors & Products Cakephp
Cakephp cakephp

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType, part, or unit values and incorporate them into generated SQL as unescaped structural fragments. An application that passes untrusted input to these parameters can permit SQL injection with confidentiality, integrity, and availability impact according to the database connection's privileges. This issue is fixed in versions 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7.
Title CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:20:00.313Z

Reserved: 2026-08-25T14:08:18.109Z

Link: CVE-2026-79752

cve-icon Vulnrichment

Updated: 2026-09-17T15:19:56.933Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T15:16:51.673

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-79752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')