CVE-2026-4317Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute arbitrary SQL commands in the database.Specifically, they could manipulate the value of the 'timezone' request parameter by including malicious characters and SQL payload. The application would interpolate these values directly into the SQL query without first performing proper filtering or sanitization (e.g., using functions such as 'prisma.rawQuery', 'prisma.$queryRawUnsafe' or raw queries with 'ClickHouse'). The successful explotation of this vulnerability could allow an authenticated attacker to compromiso the data of the database and execute dangerous functions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-31: 5Technical Details · 2026-03-31: 403-31
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Full discourse5 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Inyección SQL en la aplicación de Umami Software #CVE CVE-2026-4317 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/inyeccion-sql-en-la-aplicacion-de-umami-software #AvisosDeSeguridad #TI #CNA #0day

    Post summary

    The tweet announces an early warning about an SQL injection vulnerability (CVE-2026-4317) affecting Umami Software, but lacks details on PoC, exploitation, or remediation.

    12170651
    42.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4317 - SQL inyection in Umami Software application Intel Report: https://ift.tt/iABJPtd

    Post summary

    The alert references CVE‑2026‑4317, a SQL injection flaw in Umami Software, and points to an Intel Report for further details, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0001024
    281 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4317: SQL inyection in Umami Software a... Umami's timezone parameter bypasses Prisma ORM safety rails, allowing raw SQL injection through unsanitized interpolatio... https://zerodaysignal.com/vulnerability/CVE-2026-4317 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new CVE-2026-4317, describing a SQL injection vulnerability in Umami Software and linking to a vulnerability page, without providing PoC, exploit, patch, or evidence of active exploitation.

    0001064
    194 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4317 SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which could allow an authenticated attacker to execute a… https://www.cve.org/CVERecord?id=CVE-2026-4317

    Post summary

    The post mentions a CVE-2026-4317 SQL injection in Umami Software, providing brief technical details but no evidence of exploitation, PoC, patch, or debunking.

    00000125
    56.9K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『lo que podría permitir a un atacante autenticado ejecutar comandos SQL arbitrarios en la base de datos.』 CVE-2026-4317 Inyección SQL en la aplicación de Umami Software | INCIBE-CERT https://www.incibe.es/incibe-cert/alerta-temprana/avisos/inyeccion-sql-en-la-aplicacion-de-umami-software

    Post summary

    The CERT alert reveals that CVE-2026-4317 is a SQL injection vulnerability in Umami Software that permits authenticated attackers to execute arbitrary database commands.

    00000320
    6.7K followersView on X

Explore more