CVE-2026-34099Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. No authentication is required. An unauthenticated attacker can perform error-based SQL injection to extract the database version, current user, schema names, and table contents.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-01: 2Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 207-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Full discourse2 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-34099 — CVSS 9.8/10 ██████████ Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16):... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/19j0z6QUj5

    Post summary

    The post announces a critical unsanitized SQL injection vulnerability (CVE‑2026‑34099) in Guardian language-system and urges users to apply the patch.

    1000058
    63 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated SQL Injection in Guardian language-system job_info.php (CVE-2026-34099) CVE-2026-34099 is an SQL injection flaw in the Guardian language-system component job_info.php, where the id parameter from a GET request is used directly in a database query. The root cause is improper input validation and unsafe query construction (unsanitized SQL concatenation). An attacker can exploit this remotely over HTTP with no authentication by sending crafted id values to trigger error-based SQL injection and iteratively enumerate schemas and dump data. Real-world impact includes database reconnaissance (version/current user), full disclosure of sensitive records, and potential follow-on compromise depending on exposed credentials and application trust relationships. 👉 Affected: Guardian language-system (versions with vulnerable job_info.php id GET handling; exact range not specified) | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post discloses CVE‑2026‑34099 as an unauthenticated SQL injection in Guardian language‑system's job_info.php, detailing its exploitation method while noting no fix is available.

    00000102
    232 followersView on X

Explore more