CVE-2026-7699Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argument filtersfields results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-03: 3Technical Details · 2026-05-03: 305-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7699 SQL Injection in Dromara MaxKey Up to 3.5.13 via filtersfields Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7699

    Post summary

    This brief announcement discloses a SQL injection vulnerability in Dromara MaxKey versions up to 3.5.13 that exploits the filtersfields parameter, without providing PoC, exploit, patch, or active exploitation details.

    0000049
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7699 A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file http://StrUtils.java. Perform… https://www.cve.org/CVERecord?id=CVE-2026-7699 ----- Traducción: CVE-202… http://infoflow.cloud`

    Post summary

    The text announces the discovery of CVE-2026-7699 affecting Dromara MaxKey’s StrUtils.checkSqlInjection, but provides no PoC, exploitation evidence, or patch information.

    0000035
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7699 A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file http://StrUtils.java. Perform… https://www.cve.org/CVERecord?id=CVE-2026-7699

    Post summary

    The text announces a newly discovered CVE-2026-7699 affecting Dromara MaxKey up to version 3.5.13, specifically the StrUtils.checkSqlInjection function, and provides a link to the CVE record.

    00000235
    57.4K followersView on X

Explore more