CVE-2026-40906Disclosure(electric / sync-service)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch electric sync-service systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORDER BY expressions. This vulnerability is fixed in 1.5.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sync-service

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
sync-service

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-21: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-27: 104-2104-2204-27
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-211
Disclosure1
2026-04-221
Patch1
2026-04-271
Disclosure1
Full discourse3 posts
  • Gray Hats@the_yellow_fall
    Patch

    ElectricSQL reveals a critical 10.0 CVSS SQL injection (CVE-2026-40906). Attackers can hijack PostgreSQL and bypass tenant isolation. Patch to v1.5.0 now. #ElectricSQL #CyberSecurity #SQLi #PostgreSQL #InfoSec #DatabaseSecurity #PatchNow https://securityonline.info/electricsql-sql-injection-cve-2026-40906-database-security/ https://t.co/PYGngvZ0Rk

    Post summary

    CVE-2026-40906 is a critical SQL injection affecting ElectricSQL, vulnerable to tenant isolation bypass; a patch (v1.5.0) is available, and no active exploitation has been reported.

    11030510
    12.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40906 Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, a… https://www.cve.org/CVERecord?id=CVE-2026-40906

    Post summary

    The post discloses that Electric’s /v1/shape API (v1.1.12‑1.4.x) is vulnerable to error‑based SQL injection via the order_by parameter, with no mitigations or exploit details included.

    00010137
    57.3K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40906: Electric: SQL Injection via ORDE... Error-based SQLi in ElectricSQL's Shape API ORDER BY param = full PostgreSQL takeover with just auth creds - trivial ex... https://zerodaysignal.com/vulnerability/CVE-2026-40906 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑40906 is a disclosed error‑based SQL injection in ElectricSQL’s Shape API that allows a PostgreSQL takeover with legitimate credentials; a link is provided but no exploit tool or patch is referenced.

    0000162
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelectricsync-service---

Explore more