Upwind Security MDR[verified]@UpwindMDRPatch
CVE-2026-13766 is a critical SQL identifier injection in DBIx::QuickORM that can lead to data compromise; upgrading to version 0.000026 fixes the issue.
Open Source Security mailing list@oss_securityDisclosure
The notes announce two CVE disclosures: four in Net::BitTorrent (up to 2.0.1) and CVE‑2026‑13766 affecting DBIx::QuickORM, where unquoted SQL identifiers lead to SQL injection, with links for further details.
SecAlerts@SecAlertsCoDisclosure
The tweet announces a critical SQL injection vulnerability (CVE-2026-13766) in DBIx::QuickORM with no auth or interaction needed, and notes that a patch (v0.000026) is available. Users are urged to update immediately.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A newly disclosed SQL injection vulnerability in DBIx::QuickORM (pre‑0.000026) was announced with links to details and a notification, but no PoC, exploit code, active exploitation, patch, or false‑positive claim were provided.