CVE-2026-26198Disclosure(collerek / ormar)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch collerek ormar systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-supplied column names directly into `sqlalchemy.text()` without any validation or sanitization. The `min()` and `max()` methods in the `QuerySet` class accept arbitrary string input as the column parameter. While `sum()` and `avg()` are partially protected by an `is_numeric` type check that rejects non-existent fields, `min()` and `max()` skip this validation entirely. As a result, an attacker-controlled string is embedded as raw SQL inside the aggregate function call. Any unauthorized user can exploit this vulnerability to read the entire database contents, including tables unrelated to the queried model, by injecting a subquery as the column parameter. Version 0.23.0 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ormar

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 7 mentions (2026-02-24); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
ormar

Deep dive

Activity timeline12 mentions / 5d
02457Mentions · 2026-02-24: 7Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Mentions · 2026-02-28: 2Mentions · 2026-03-01: 1Patch / Workaround · 2026-02-24: 3Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-24: 7Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2502-2602-2803-01
Signal classification3 categories
Disclosure
650.0%
Patch
541.7%
General
18.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-247
Disclosure4Patch3
2026-02-251
Patch1
2026-02-261
Patch1
2026-02-282
Disclosure1General1
2026-03-011
Disclosure1
Full discourse12 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical SQL injection flaw (CVE-2026-26198) in ormar Python ORM allows unauthenticated attackers to leak entire databases. Update to version 0.23.0 immediately! #Python #FastAPI #SQLInjection #CVE #AppSec #InfoSec #CyberSecurity #DatabaseSecurity https://securityonline.info/critical-sql-injection-vulnerability-found-in-ormar-python-library/

    Post summary

    The post announces a critical SQL injection flaw in ormar Python ORM (CVE-2026-26198) that permits unauthenticated database leakage and urges users to update to version 0.23.0.

    10010302
    10.4K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26198: CRITICAL] Ormar, a Python async mini ORM, had a vulnerability in versions 0.9.9 to 0.22.0, allowing attackers to read entire database contents. Update to version 0.23.0 for the patch.#cve,CVE-2026-26198,#cybersecurity https://cvefind.com/CVE-2026-26198

    Post summary

    CVE‑2026‑26198 in Ormar permits full database reads; a patch is available in version 0.23.0.

    1000071
    584 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26198 (CVSS:9.8, CRITICAL) is Analyzed. Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM con..https://nvd.nist.gov/vuln/detail/CVE-2026-26198 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-26198, a critical vulnerability in Ormar ORM affecting aggregate queries in versions 0.9.9–0.22.0, with CVSS 9.8, but no PoC, exploit, or patch details are provided.

    0000049
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26198 (CVSS:9.8, CRITICAL) is Analyzed. Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM con..https://nvd.nist.gov/vuln/detail/CVE-2026-26198 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces the critical CVE-2026-26198 affecting Ormar's aggregate queries, providing severity but no PoC, exploit, or patch details.

    0000031
    173 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full information about CVE-2026-26198 from https://vulntracker.io/cves/CVE-2026-26198

    Post summary

    The tweet points readers to a vulnerability tracker page for CVE-2026-26198 but provides no further information.

    0000042
    352 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical SQL injection vulnerability (CVE-2026-26198) in `ormar` ORM affects versions 0.9.9-0.22.0 during aggregate queries. Update to 0.23.0 or later to mitigate. #Python #SQLi #Security https://www.pulsepatch.io/posts/ubuntu-cve-2026-26198-ormar-sql-injection

    Post summary

    The post announces a critical SQL injection in ormar ORM and advises updating to version 0.23.0 or later to mitigate.

    0000040
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Ormar` users: CVE-2026-26198 details a critical #SQLi vulnerability in `min()`/`max()` aggregate functions. Update `ormar` to v0.23.0. #Python #infosec https://www.pulsepatch.io/posts/cve-2026-26198-ormar-sql-injection

    Post summary

    CVE-2026-26198 is a critical SQL injection affecting Ormar’s min()/max() aggregate functions; users are advised to upgrade to v0.23.0 to mitigate the risk.

    0000059
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26198 SQL Injection Injection in Ormar OOORM 0.9.9Through-0..22.via.0via Aggregate Query Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26198

    Post summary

    A SQL injection vulnerability affecting Ormar OOORM versions 0.9.9 to 0.22 via aggregate query manipulation has been disclosed.

    0000062
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26198 Ormar is a async mini ORM for Python. In versions 0.9.9 through 0.22.0, when performing aggregate queries, Ormar ORM constructs SQL expressions by passing user-suppli… https://www.cve.org/CVERecord?id=CVE-2026-26198

    Post summary

    The text announces a SQL injection vulnerability in Ormar’s aggregate queries, detailing affected versions but providing no PoC, exploit, or patch information.

    00000107
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26198: Ormar's Aggregate Amnesia: Critical SQL Injection in min() and max() A critical SQL injection vulnerability in the Ormar Python ORM allows attackers to execute arbitrary subqueries via the min() and max() aggregate functions. While num... https://cvereports.com/reports/CVE-2026-26198

    Post summary

    The report announces a critical SQL injection in Ormar’s min() and max() functions that permits arbitrary subqueries, but it provides no PoC, exploit code, or patch information.

    0000050
    31 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨CRITICAL: SQL injection in Ormar (Python ORM) v0.9.9 – 0.22.0 lets attackers read any DB data, no auth needed! Upgrade to v0.23.0+ ASAP. https://radar.offseq.com/threat/cve-2026-26198-cwe-89-improper-neutralization-of-s-7460e41f #OffSeq #SQLInjection #PythonSecurity https://t.co/9dZQh7b13I

    Post summary

    The tweet warns of a critical SQL injection in Ormar v0.9.9–0.22.0 that allows unauthenticated data reading and urges users to upgrade to v0.23.0+.

    0000050
    269 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-26198 pertains to a critical security flaw in the Ormar ORM (Object-Relational Mapper) for Python, specifically affecting versions 0.9.9 through 0.22.0. The vulnerability arises during the execution of aggregate queries (`min()` and `max()` methods) where user-supplied column names are directly embedded into SQL expressions via `sqlalchemy.text()` without proper validation or sanitization. This oversight allows attackers to inject malicious SQL code through the column parameter, leading to potential SQL injection attacks. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #SQLInjection #DDoS https://cvetodo.com/cve/CVE-2026-26198

    Post summary

    CVE-2026-26198 is a critical SQL injection flaw in the Ormar ORM caused by unsanitized column names in aggregate queries, affecting versions 0.9.9 through 0.22.0.

    0000051
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcollerekormar-python-

Explore more