CVE-2026-13766Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass, sets bindtype in its constructor but never quote_char, so SQL::Abstract emits identifiers verbatim. Caller-supplied identifiers (order_by, where-clause column keys, field and returning lists, upsert columns, and join aliases) reach the SQL string raw, while values are placeholder-bound and unaffected. A caller that forwards untrusted input to an affected identifier position, such as a user-controlled order_by value, enables SQL injection: the row order can be made to depend on a sub-select over columns the query never selected, and the where and update identifier positions permit further data disclosure and tampering.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-06-30); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-01: 1Mentions · 2026-07-05: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-01: 1Technical Details · 2026-07-05: 106-3007-0107-05
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure1Patch1
2026-07-011
Disclosure1
2026-07-051
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Perl CPAN 4 CVEs in Net::BitTorrent through 2.0.1 https://www.openwall.com/lists/oss-security/2026/06/30/3 CVE-2026-13766: DBIx::QuickORM before 0.000026 allow SQL injection via unquoted SQL identifiers https://www.openwall.com/lists/oss-security/2026/06/30/4

    Post summary

    The notes announce two CVE disclosures: four in Net::BitTorrent (up to 2.0.1) and CVE‑2026‑13766 affecting DBIx::QuickORM, where unquoted SQL identifiers lead to SQL injection, with links for further details.

    10000185
    4.7K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    SQL injection via unquoted identifiers in DBIx::QuickORM (Perl ORM) — CVSS 9.8 critical. No auth, no interaction needed. Fix landed in v0.000026. If you're using this ORM, update now. CVE-2026-13766 🐪 https://secalerts.co/vulnerability/CVE-2026-13766?utm_campaign=x https://t.co/PGhNzioX5w

    Post summary

    The tweet announces a critical SQL injection vulnerability (CVE-2026-13766) in DBIx::QuickORM with no auth or interaction needed, and notes that a patch (v0.000026) is available. Users are urged to update immediately.

    0000176
    847 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - DBIx::QuickORM SQL identifier injection (CVE-2026-13766) DBIx::QuickORM contains a SQL injection flaw where SQL identifiers (e.g., column names, ORDER BY fields, JOIN aliases) are emitted verbatim into generated queries without proper quoting/escaping. The root cause is improper input validation and unsafe SQL construction in identifier positions rather than value placeholders. An attacker can exploit this by supplying crafted identifier inputs via any untrusted caller-controlled parameters that map to order_by, where-clause column keys, field/returning lists, upsert columns, or join aliases, requiring only the ability to influence query-building inputs. Successful exploitation can lead to data disclosure, unauthorized data modification, and potentially broader database compromise depending on the connected DB user privileges. 👉 Affected: DBIx::QuickORM < 0.000026 | Upgrade to 0.000026

    Post summary

    CVE-2026-13766 is a critical SQL identifier injection in DBIx::QuickORM that can lead to data compromise; upgrading to version 0.000026 fixes the issue.

    0000060
    232 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13766 SQL Injection in DBIx::QuickORM Before 0.000026 via Unquoted Identifiers https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13766 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A newly disclosed SQL injection vulnerability in DBIx::QuickORM (pre‑0.000026) was announced with links to details and a notification, but no PoC, exploit code, active exploitation, patch, or false‑positive claim were provided.

    00000126
    4.1K followersView on X

Explore more